Buletin de securitate cibernetică – 5 septembrie 2026

Cybersecurity Bulletin – 5 September 2026

The CyberSec Intelligence team presents its daily security bulletin for 5 September 2026. We review actively exploited vulnerabilities in the CISA KEV catalogue, new critical NVD entries and recent reporting from the…

The CyberSec Intelligence team presents its daily security bulletin for 5 September 2026. We review actively exploited vulnerabilities in the CISA KEV catalogue, new critical NVD entries and recent reporting from the international security press.

Actively exploited vulnerabilities

  • CVE-2026-85046 (Google Chromium V8) – Type confusion allowing remote arbitrary code execution inside the sandbox through a crafted HTML page.
  • CVE-2026-59822 (BerriAI LiteLLM) – Improper authentication in the HTTP MCP Streamable endpoint allows an unauthenticated attacker to establish a valid session with an arbitrary Bearer token.
  • CVE-2026-48710 (Kludex Starlette) – HTTP request/response smuggling can inject host paths and bypass URL-reconstruction authentication.
  • CVE-2026-49869 (Kestra OSS) – Unauthenticated OS command injection allows arbitrary workflows to be created and executed.
  • CVE-2026-82329 (JFrog Artifactory) – A default authentication weakness can grant administrative privileges to an unauthenticated network attacker.
  • CVE-2026-9586 (Sangoma Switchvox) – Unauthenticated remote SQL injection may lead to arbitrary SQL commands and remote code execution.
  • CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000) – SSRF and administrator-level OS command injection expose sensitive appliance functions.
  • CVE-2026-82078 / CVE-2026-81578 (PaperCut NG/MF) – Unsafe reflection and missing authentication allow configuration changes and arbitrary Java bytecode execution.

Critical new vulnerabilities

New high-impact entries include a buffer overflow in TOTOLINK CP450, insecure socket.io configuration in Taipy, asymmetric-key validation flaws in python-jose, authentication bypasses in MOOS components, WordPress Divi local file inclusion, path confinement issues in excel-mcp-server, webhook validation flaws and multiple unauthenticated file or command injection issues.

What to do

Prioritise patches for internet-facing systems, review exposure to the affected products and monitor authentication and administrative activity. A vulnerability that is only “on the list” is still a problem if the system is reachable and forgotten.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *