Buletin de securitate cibernetică – 6 septembrie 2026

Cybersecurity Bulletin – September 6, 2026

Daily vulnerability analysis: 10 actively exploited flaws, new critical breaches in WordPress and AI services, plus security news from September 6, 2026.

The CyberSec Intelligence security bulletin from September 6, 2026, highlights a series of major vulnerabilities reported recently. We closely monitor new zero-day threats and breaches in the software ecosystem to ensure the digital resilience of organizations.

n

Actively exploited vulnerabilities

n

    n

  • CVE-2026-85046 (Google Chromium V8): A Type Confusion vulnerability allows remote attackers to execute arbitrary code via malicious HTML pages. Affects Chromium-based browsers such as Chrome, Edge, and Opera. Details: NVD CVE-2026-85046.
  • n

  • CVE-2026-59822 (BerriAI LiteLLM): Improper authentication in the HTTP MCP Streamable endpoint, allowing unauthenticated attackers to establish a valid session using an arbitrary Bearer token. Details: NVD CVE-2026-59822.
  • n

  • CVE-2026-48710 (Kludex Starlette): Request/response smuggling vulnerability that can lead to authentication bypass by manipulating the reconstructed URL path (can be correlated with CVE-2026-42271). Details: NVD CVE-2026-48710.
  • n

  • CVE-2026-49869 (Kestra Kestra OSS): Command injection in the operating system, allowing an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Details: NVD CVE-2026-49869.
  • n

  • CVE-2026-82329 (JFrog Artifactory): An improper authentication flaw in the default configuration that allows unauthenticated network attackers to obtain administrative privileges. Details: NVD CVE-2026-82329.
  • n

  • CVE-2026-9586 (Sangoma Switchvox): SQL injection allowing remote attackers to run arbitrary queries on the PostgreSQL database and execute remote code. Details: NVD CVE-2026-9586.
  • n

  • CVE-2026-83548 (SonicWall SMA1000): A Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to obtain unauthorized access to sensitive functions. Details: NVD CVE-2026-83548.
  • n

  • CVE-2026-83549 (SonicWall SMA1000): Operating system command injection allowing an attacker authenticated as administrator to run arbitrary code on the device. Details: NVD CVE-2026-83549.
  • n

  • CVE-2026-82078 (PaperCut NG/MF): Insecure reflection allowing attackers to modify system parameters and execute Java bytecode (can be combined with CVE-2026-81578). Details: NVD CVE-2026-82078.
  • n

  • CVE-2026-81578 (PaperCut NG/MF): Missing authentication for critical functions, offering attackers the ability to modify system configurations without credentials. Details: NVD CVE-2026-81578.
  • n

n

New critical vulnerabilities

n

    n

  • CVE-2026-11613 (WordPress plugin Divi Ajax Filter): Local File Inclusion (LFI) via the ‘custom_loop_template’ parameter allowing unauthenticated attackers to execute arbitrary remote PHP code. Details: NVD CVE-2026-11613.
  • n

  • CVE-2026-85661 (excel-mcp-server): Missing path restriction in stdio mode when the EXCEL_FILES_PATH variable is not defined, allowing arbitrary file read and write. Details: NVD CVE-2026-85661.
  • n

  • CVE-2026-85667 (xiaobei): Missing authentication on webhook endpoints, facilitating SSRF attacks and malicious message injection into the workflow. Details: NVD CVE-2026-85667.
  • n

  • CVE-2026-85672 (zerox): System command injection in the file download mechanism via unsanitized file extensions used by poppler utilities. Details: NVD CVE-2026-85672.
  • n

  • CVE-2026-85684 (marker): Path traversal in the FastAPI upload API (/marker/upload), allowing arbitrary file write or deletion in the system. Details: NVD CVE-2026-85684.
  • n

  • CVE-2026-85688 (TEN Framework): Unauthenticated file read and write in the designer API, allowing RCE by compromising SSH keys, cron, or executable flows. Details: NVD CVE-2026-85688.
  • n

  • CVE-2026-85695 (FastChat): Authentication bypass during registration of new instances (workers), which can be used to intercept user prompts or perform internal network scans. Details: NVD CVE-2026-85695.
  • n

  • CVE-2026-85696 (SadTalker): OS command injection via unsanitized audio filenames passed to ffmpeg commands. Details: NVD CVE-2026-85696.
  • n

  • CVE-2026-18658 (IBM Operational Decision Manager): SQL injection that can lead to uploading a web shell to the application root and executing remote code. Details: NVD CVE-2026-18658.
  • n

  • CVE-2026-13447 (WordPress plugin Mstore Api): Authentication bypass through JWT token forgery, caused by the missing cryptographic verification of signatures. Details: NVD CVE-2026-13447.
  • n

  • CVE-2026-83627 (WordPress plugin Hummingbird): Remote code execution by writing unsanitized PHP code into a log file directly accessible from the browser in certain configurations. Details: NVD CVE-2026-83627.
  • n

  • CVE-2024-11080 (WordPress plugin ComboBlocks): Unauthenticated injection of hooks into internal files, allowing unauthorized actions to be executed. Details: NVD CVE-2024-11080.
  • n

n

From the security press

n

    n

  • StyleSmuggler (Zero-Day not associated with a CVE): Attackers are actively exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce that allows code execution without authentication. Details: The Hacker News.
  • n

  • JetBrains Cadence Incident: Malicious actors exploited a recent breach in TeamCity to compromise JetBrains Cadence infrastructure and extract AWS credentials. Users are advised to urgently revoke and rotate their secrets. Details: The Hacker News.
  • n

  • CVE-2026-59346 (VMware Workstation and Fusion): An integer overflow error allows a local attacker with elevated privileges to execute code directly on the host system. Details: The Hacker News.
  • n

  • CVE-2026-14894 (WordPress plugin Super Forms): Over 440,000 exploit attempts targeted this missing file extension validation vulnerability, which allows unauthenticated attackers to achieve RCE. Details: The Hacker News.
  • n

n

What we recommend

n

    n

  • Patch Management: Apply official security updates immediately, prioritizing currently exposed platforms (Chromium, Magento, WordPress, and enterprise software).
  • n

  • Asset Inventory: Maintain a clear inventory of used services, focusing on the integration of new AI-based tools (such as MCP modules or LiteLLM) to quickly detect unprotected instances.
  • n

  • Monitoring and rotation of secret keys: Constantly monitor access logs and ensure the urgent rotation of credentials or API keys (especially after breaches such as the JetBrains Cadence one).
  • n

n

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *