Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

01 September 2026

12 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.

One week of Security Weekly Digest, 6 stories, as published.

Exploited CVEs

CVE-2026-82078: PaperCut NG/MF

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

Why it matters — Confirmed exploited in the wild. CVSS 9.4 (CRITICAL). CISA remediation deadline 14 Sep 2026 — 13 days out.

CISA KEV · 01 September 2026 · Read the original →

Exploited CVEs

CVE-2023-49105: ownCloud

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 30 Aug 2026 — already passed.

CISA KEV · 01 September 2026 · Read the original →

Exploited CVEs

CVE-2026-60004: Gitea

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 28 Aug 2026 — already passed.

CISA KEV · 01 September 2026 · Read the original →

Exploited CVEs

CVE-2026-53362: Linux Kernel

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

Why it matters — Confirmed exploited in the wild. CVSS 7.8 (HIGH). CISA remediation deadline 30 Aug 2026 — already passed.

CISA KEV · 01 September 2026 · Read the original →

Exploited CVEs

CVE-2021-23758: Ajax.NET Professional

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Why it matters — Confirmed exploited in the wild. CVSS 8.1 (HIGH). CISA remediation deadline 09 Sep 2026 — 8 days out.

CISA KEV · 01 September 2026 · Read the original →

Exploited CVEs

CVE-2015-5287: Red Hat Automatic Bug Reporting Tool

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Why it matters — Confirmed exploited in the wild. CVSS 7.8 (HIGH). CISA remediation deadline 09 Sep 2026 — 8 days out.

CISA KEV · 01 September 2026 · Read the original →

Our patch cycle appears to have lost all concept of linear time.

6 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →