Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

08 September 2026

8 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.

One week of Security Weekly Digest, 9 stories, as published.

Exploited CVEs

CVE-2026-49869: Kestra OSS

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 05 Sep 2026 — already passed.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-82329: JFrog Artifactory

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 05 Sep 2026 — already passed.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-9586: Sangoma Switchvox

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Why it matters — Confirmed exploited in the wild. CVSS 9.3 (CRITICAL). CISA remediation deadline 05 Sep 2026 — already passed.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-83548: SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 05 Sep 2026 — already passed.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-85046: Google Chromium V8

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 18 Sep 2026 — 10 days out.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-59822: BerriAI LiteLLM

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 16 Sep 2026 — 8 days out.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-48710: Kludex Starlette

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Why it matters — Confirmed exploited in the wild. CVSS 6.5 (MEDIUM). CISA remediation deadline 16 Sep 2026 — 8 days out.

CISA KEV · 08 September 2026 · Read the original →

Exploited CVEs

Langflow and Rails Flaws Actively Exploited

Threat actors are actively exploiting critical vulnerabilities in Langflow (CVE-2026-0768) and Ruby on Rails (CVE-2026-66066) as of September 1, 2026. The Langflow flaw allows arbitrary Python code execution, while the Rails vulnerability enables unauthenticated attackers to read arbitrary files and potentially achieve remote code execution, leading to credential harvesting and command-and-control activity.

Why it matters — Organizations using Langflow or Ruby on Rails with Active Storage and libvips must immediately patch to prevent unauthenticated remote code execution and data exposure.

The Hacker News · 08 September 2026 · Read the original →

Supply Chain

Magento/Adobe Commerce 0-Day Exploited

E-commerce storefronts are being compromised by an unpatched Magento and Adobe Commerce zero-day vulnerability, dubbed StyleSmuggler, which allows unauthenticated attackers remote code execution. Attacks commenced on September 4, 2026, injecting malicious code into Magento's template system to evade existing safeguards.

Why it matters — E-commerce platforms running Magento or Adobe Commerce must apply emergency mitigations or patches to prevent unauthenticated remote code execution and store backdooring.

The Hacker News · 08 September 2026 · Read the original →

At this point, the vulnerability scanner is basically writing our sprint backlog.

9 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →