May 8, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • BerriAI LiteLLM added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2026-42208 BerriAI LiteLLM SQL Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

BerriAI LiteLLM SQL Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2026-42298 Postiz is an AI social media scheduling tool.

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical Gitroom Postiz privilege escalation (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-42160 Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline...

  • CVSS 10
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-42072 CVSS 9.8

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes.

CVE-2026-42160 CVSS 10

Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management.

CVE-2026-42193 CVSS 9.1

Plunk is an open-source email platform built on top of AWS SES.

CVE-2026-42287 CVSS 10

Emlog is an open source website building system.

CVE-2026-42298 CVSS 10

Postiz is an AI social media scheduling tool.

CVE-2026-42354 CVSS 9.1

Sentry is an error tracking and performance monitoring tool.

CVE-2026-42454 CVSS 9.9

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities.

CVE-2026-44313 CVSS 9.1

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages.

CVE-2026-8178 CVSS 9.2

An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2.

View critical disclosures

cvelogic Threat Intelligence