May 22, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Drupal Core added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2026-9082 Drupal Core SQL Injection

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Drupal Core SQL Injection is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2026-23652 Microsoft Power Pages Command Injection

  • CVSS 10

New critical Microsoft Power Pages Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2026-41104 Microsoft Planetary Computer Deserialization

  • CVSS 10

New critical Microsoft Planetary Computer Deserialization (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-23652 CVSS 10

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attac...

CVE-2026-33843 CVSS 9.1

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to eleva...

CVE-2026-40411 CVSS 9.9

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

CVE-2026-40412 CVSS 10

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

CVE-2026-41090 CVSS 9.3

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker...

CVE-2026-41104 CVSS 10

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a netw...

CVE-2026-42901 CVSS 10

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-47280 CVSS 10

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-48700 CVSS 9.3

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0.

View critical disclosures

cvelogic Threat Intelligence