May 7, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Ivanti Endpoint Manager Mobile (EPMM) added to CISA KEV — confirmed in-the-wild exploitation.
  • Bludit: public exploit or PoC linked (RCE)
  • Maxum Development Corporation Rumpus Ftp Server — exploitation likelihood rose sharply (EPSS 6.9% → 24% · rising (+17%)).
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

Ivanti Endpoint Manager Mobile (EPMM) RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2025-34282 Thingsboard SSRF

  • Public exploit or PoC available
  • Exploit activity linked

Thingsboard SSRF now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Emerging exploitation risk

CVE-2007-0019 Maxum Development Corporation Rumpus Ftp Server Buffer Overflow

  • Exploitation likelihood sharply increased
  • EPSS 6.9% → 24% · rising (+17%)

Maxum Development Corporation Rumpus Ftp Server: EPSS 6.9% → 24% · rising (+17%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation

View KEV additions

Exploit & PoC activity

CVE-2026-34156 Exploit

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions.

CVE-2026-25099 Exploit

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction...

CVE-2026-32746 Exploit

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because a...

CVE-2026-26980 Exploit

Ghost is a Node.js content management system.

CVE-2025-34282 Exploit

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature.

View new exploit links

Exploitation dynamics

CVE-2007-0019 EPSS 6.9% → 24% · rising (+17%) CVSS 6.5

Maxum Development Corporation Rumpus Ftp Server Buffer Overflow

CVE-2020-2036 EPSS 61% → 78% · rising (+17%) CVSS 8.8

Paloaltonetworks Pan-os XSS

CVE-2002-1156 EPSS 26% → 39% · rising (+12%) CVSS 5

Apache Http Server

CVE-2006-0710 EPSS 6.2% → 17% · rising (+11%) CVSS 7.5

Isode M-vault Server

See EPSS increases

New critical disclosures

CVE-2026-33109 CVSS 9.9

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

CVE-2026-33823 CVSS 9.6

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

CVE-2026-35428 CVSS 9.6

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker...

CVE-2026-37709 CVSS 9.8

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote...

CVE-2026-41902 CVSS 9.1

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework.

CVE-2026-42826 CVSS 10

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a...

CVE-2026-42880 CVSS 9.6

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

CVE-2026-7415 CVSS 9.8

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs.

CVE-2026-7891 CVSS 9.3

The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration.

View critical disclosures

cvelogic Threat Intelligence