May 12, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2026-42288 ChurchCRM is an open-source church management system.

  • CVSS 10
  • Remote code execution exposure

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2026-42196 django-s3file is a lightweight file upload input for Django and Amazon S3.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2026-43948 wger is a free, open-source workout and fitness manager.

  • CVSS 9.9
  • Potential privilege escalation to admin/root

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

Thymeleaf is a server-side Java template engine for web and standalone environments.

CVE-2026-42196 CVSS 9.9

django-s3file is a lightweight file upload input for Django and Amazon S3.

CVE-2026-42288 CVSS 10

ChurchCRM is an open-source church management system.

CVE-2026-42854 CVSS 9.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers.

CVE-2026-43948 CVSS 9.9

wger is a free, open-source workout and fitness manager.

CVE-2026-44262 CVSS 9.4

Scramble generates API documentation for Laravel project.

CVE-2026-44547 CVSS 9.6

ChurchCRM is an open-source church management system.

CVE-2026-45185 CVSS 9.8

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.

View critical disclosures

cvelogic Threat Intelligence