08 September 2026
8 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.
CVE-2026-49869: Kestra OSS
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-82329: JFrog Artifactory
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-9586: Sangoma Switchvox
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-83548: SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-85046: Google Chromium V8
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-59822: BerriAI LiteLLM
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
CISA KEV · 08 September 2026 · Read the original →
CVE-2026-48710: Kludex Starlette
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CISA KEV · 08 September 2026 · Read the original →
Langflow and Rails Flaws Actively Exploited
Threat actors are actively exploiting critical vulnerabilities in Langflow (CVE-2026-0768) and Ruby on Rails (CVE-2026-66066) as of September 1, 2026. The Langflow flaw allows arbitrary Python code execution, while the Rails vulnerability enables unauthenticated attackers to read arbitrary files and potentially achieve remote code execution, leading to credential harvesting and command-and-control activity.
The Hacker News · 08 September 2026 · Read the original →
Magento/Adobe Commerce 0-Day Exploited
E-commerce storefronts are being compromised by an unpatched Magento and Adobe Commerce zero-day vulnerability, dubbed StyleSmuggler, which allows unauthenticated attackers remote code execution. Attacks commenced on September 4, 2026, injecting malicious code into Magento's template system to evade existing safeguards.
The Hacker News · 08 September 2026 · Read the original →
At this point, the vulnerability scanner is basically writing our sprint backlog.
9 stories, every Tuesday
Published here every week. Follow by RSS to get it as it lands.