May 14, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Cisco Catalyst SD-WAN added to CISA KEV — confirmed in-the-wild exploitation.
  • Epati Antikor Next Generation Firewall: public exploit or PoC linked (Auth Bypass)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Network edge / SD-WAN deployments affected

Cisco Catalyst SD-WAN Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2026-25994 PJSIP is a free and open source multimedia communication library written in C.

  • Public exploit or PoC available
  • Exploit activity linked

Pjsip Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2026-44523 Note Mark is an open-source note-taking application.

  • CVSS 10

New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Cisco Catalyst SD-WAN Controller Authentication Bypass

View KEV additions

Exploit & PoC activity

CVE-2026-4257 Exploit

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Executio...

CVE-2026-2624 Exploit

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc.

CVE-2026-25994 Exploit

PJSIP is a free and open source multimedia communication library written in C.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-44212 CVSS 9.3

PrestaShop is an open source e-commerce web application.

CVE-2026-44523 CVSS 10

Note Mark is an open-source note-taking application.

CVE-2026-44588 CVSS 9.4

SiYuan is an open-source personal knowledge management system.

CVE-2026-44592 CVSS 9.4

Gradient is a nix-based continuous integration system.

CVE-2026-44666 CVSS 9.3

HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool.

CVE-2026-44670 CVSS 9.4

SiYuan is an open-source personal knowledge management system.

SiYuan is an open-source personal knowledge management system.

CVE-2026-8511 CVSS 9.6

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a cra...

CVE-2026-8580 CVSS 9.6

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a c...

CVE-2026-8634 CVSS 9.3

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or comp...

View critical disclosures

cvelogic Threat Intelligence