The critical picture, at a glance.
What’s landing, who’s most exposed, and how dangerous it really is right now.
Spiking now
what’s blowing upCVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that lets unauthenticated attackers access restricted functions or data. It has a CVSS score of 9.8 and is known exploitation. CISA advises applying vendor-provided mitigations or discontinuing use of the product if mitigations are not available.
- added to CISA KEV
- 100% likely to be exploited
Microsoft SharePoint Server is vulnerable to a critical deserialization flaw that lets attackers run arbitrary code over the network. The flaw affects on‑premises SharePoint Server 2016 and 2019, and any public‑facing instances that are no longer supported. Microsoft is testing a fix, but users should apply the mitigations outlined by CISA and disconnect unsupported servers.
- added to CISA KEV
- 100% likely to be exploited
Rejetto HTTP File Server up to version 2.3m contains a critical template injection flaw that lets attackers run arbitrary commands on the server. The vulnerability is remote, requires no authentication or user interaction, and is no longer supported by the vendor.
- added to CISA KEV
- 99% likely to be exploited
Apache Tomcat’s default AJP connector can be exploited by attackers to read arbitrary files and execute code. The vulnerability allows remote code execution if the connector is reachable from untrusted networks. It is critical because it can compromise any Tomcat instance exposed to the internet.
- added to CISA KEV
- 99% likely to be exploited
A path‑traversal flaw in Mitel MiCollab’s NuPoint Unified Messaging component (up to version 9.8 SP1 FP2) lets an attacker read, change, or delete data without logging in. The bug is triggered by unsanitized input that can reach files outside the intended directory.
- added to CISA KEV
- 98% likely to be exploited
Zimbra Collaboration Suite versions 8.8.15 and 9.0 are vulnerable to a critical flaw that lets attackers upload arbitrary files via the amavis mail filter. The flaw uses a cpio extraction bug to place files in a public web directory, allowing attackers to access other users’ data. The issue is fixed by applying vendor‑supplied updates.
- added to CISA KEV
- 95% likely to be exploited