Active exploitation and KEV inclusion now combine with very high EPSS on an internet-facing edge product.
Confirm exposure, patch now and review appliance activity.Daily operational briefing
What changed?
The evidence that changed vulnerability priority today, distilled into the decisions that matter.
Today’s movement
Analyst summary
Edge infrastructure remains the clearest priority. Two vulnerabilities gained authoritative exploitation evidence, while several high-CVSS desktop issues remain low signal.
Prioritised by evidence
What I’d look at first
A public exploit and KEV inclusion materially increase the likelihood of targeting.
Patch exposed servers and run compromise checks.EPSS is rising and a proof of concept is public, but exploitation is not yet confirmed.
Validate affected versions and internet exposure today.Evidence changes
Change feed
FortiOS command injection
Added to the demonstration KEV set after exploitation evidence was reported.
Exchange Server remote code execution
Public exploit availability and KEV status changed the remediation window.
Cisco Secure Firewall memory corruption
EPSS increased from 52.1% to 74.4% in the fictional data set.
Ivanti Connect Secure access-control bypass
No confirmed exploitation, but the product remains attractive and commonly exposed.
Vendor intelligence
Significant advisories
Context over severity
What I wouldn’t overreact to
Adobe Acrobat memory safety flaw
CVSS 9.8, but EPSS remains 0.4% with no exploitation evidence. Keep it in the normal patch cycle.
Local privilege escalation
Requires authenticated local access and has no public exploit or credible activity.
Development dependency denial of service
Limited production exposure and no meaningful movement in exploitation probability.