May 11, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations...

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2026-42864 FireFighter is an incident management application.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2026-38567 HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-34260 CVSS 9.6

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malic...

CVE-2026-34263 CVSS 9.6

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, re...

CVE-2026-38567 CVSS 9.8

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints.

CVE-2026-42864 CVSS 9.9

FireFighter is an incident management application.

CVE-2026-42869 CVSS 10

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs.

CVE-2026-42882 CVSS 9.4

oxyno-zeta/s3-proxy is an aws s3 proxy written in go.

CVE-2026-43899 CVSS 9.6

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents.

CVE-2026-43900 CVSS 9.3

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents.

CVE-2026-7813 CVSS 9.4

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger...

View critical disclosures

cvelogic Threat Intelligence