Today, September 7, 2026, we present a summary of the latest cyber threats and vulnerabilities. We recommend that technical teams analyze and prioritize security updates to reduce the risk of compromise.
Actively exploited vulnerabilities
- CVE-2026-85046 (Google Chromium V8): Type confusion vulnerability that allows a remote attacker to execute arbitrary code in the sandbox through malicious HTML pages. Affects Google Chrome, Microsoft Edge, and Opera. CVE-2026-85046 Details
- CVE-2026-59822 (BerriAI LiteLLM): Improper authentication in the MCP Streamable HTTP endpoint, allowing unauthenticated attackers to establish authorized sessions using arbitrary Bearer tokens. CVE-2026-59822 Details
- CVE-2026-48710 (Kludex Starlette): HTTP request/response smuggling vulnerability that allows path injection in the host header, facilitating authentication bypass. It can be correlated with CVE-2026-42271. CVE-2026-48710 Details
- CVE-2026-49869 (Kestra Kestra OSS): OS command injection defect that allows unauthenticated attackers to create and execute arbitrary workflows without credentials. CVE-2026-49869 Details
- CVE-2026-82329 (JFrog Artifactory): Broken authentication issue in the default configuration, giving network attackers the ability to obtain administrator privileges. CVE-2026-82329 Details
- CVE-2026-9586 (Sangoma Switchvox): SQL Injection vulnerability in the PostgreSQL backend database, giving remote attackers the ability to execute arbitrary queries and remote code. CVE-2026-9586 Details
- CVE-2026-83548 (SonicWall SMA1000): Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to access sensitive device features. CVE-2026-83548 Details
- CVE-2026-83549 (SonicWall SMA1000): OS command injection that allows an authenticated administrator to execute arbitrary commands on the device’s operating system. CVE-2026-83549 Details
- CVE-2026-82078 (PaperCut NG/MF): Unsafe reflection vulnerability, allowing an attacker to modify configuration and run malicious Java bytecode (can be associated with CVE-2026-81578). CVE-2026-82078 Details
- CVE-2026-81578 (PaperCut NG/MF): Missing authentication for critical functions, giving attackers the option to alter system configurations (can be associated with CVE-2026-82078). CVE-2026-81578 Details
New critical vulnerabilities
- CVE-2026-13447 (WordPress Plugin Mstore Api): Allows authentication bypass by forging JWT tokens due to missing cryptographic signature validation. CVE-2026-13447 Details
- CVE-2026-83627 (WordPress Plugin Hummingbird): Remote Code Execution (RCE) via the ability to write unsanitized PHP code into the page cache log file. CVE-2026-83627 Details
- CVE-2024-11080 (WordPress Plugin Post Grid and Gutenberg Blocks): Allows unauthenticated injection of hooks into function.php file functions, facilitating unauthorized action execution. CVE-2024-11080 Details
- CVE-2026-86121 (Cua computer-server): Complete authentication bypass when the CONTAINER_NAME environment variable is not set, allowing shell command execution as root and file reading/writing. CVE-2026-86121 Details
- CVE-2026-86124 (AutoAgent): Unauthenticated remote command execution on the exposed TCP server, allowing attackers to run bash commands with root privileges. CVE-2026-86124 Details
- CVE-2026-10196 (WordPress Plugin Mail Mint): Allows PHP Object Injection through insecure deserialization of data in the handle_form_submission function, leading to code execution on the server. CVE-2026-10196 Details
- CVE-2026-86184 (Lara Dashboard): Authentication bypass on the screenshot-login route when the environment is not configured as production, allowing easy access to the administrator account. CVE-2026-86184 Details
- CVE-2026-86189 (WWBN AVideo): Path traversal defect in the notify.ffmpeg.json.php component that gives attackers the ability to write arbitrary files on the server. CVE-2026-86189 Details
- CVE-2026-86190 (WWBN AVideo): Broken access control in the videoViewsInfo endpoints, exposing password hashes and tokens used for session hijacking. CVE-2026-86190 Details
- CVE-2026-86148 (Tenda CP3): OS command injection via the AlarmVoiceURL argument in the Apis/system.c file. CVE-2026-86148 Details
- CVE-2026-86149 (Tenda CP3): OS command injection vulnerability in NetCheckPing.cpp when processing interface or host arguments. CVE-2026-86149 Details
- CVE-2026-86151 (Tenda CP3): OS command injection in the sub_2F77E8 function associated with network configuration management. CVE-2026-86151 Details
From the security press
- StyleSmuggler (no CVE) – Magento & Adobe Commerce: Unpatched zero-day vulnerability actively exploited since the beginning of September. Attackers can run malicious code on online store servers without authenticating. The Hacker News Article
- JetBrains Cadence Compromise (no CVE): Attackers exploited a critical vulnerability in TeamCity to compromise the JetBrains Cadence environment and extract AWS credentials. The Hacker News Article
- CVE-2026-59346 – VMware Workstation and Fusion: An integer-overflow error in VMware platforms allows local users with elevated privileges to execute arbitrary code directly on the host machine. The Hacker News Article
What we recommend
- Patch Management: Promptly apply security patches provided by vendors for Chromium-based browsers, VMware products, Magento CMS, targeted WordPress plugins, and SonicWall or Tenda devices.
- Asset Inventory and Disabling Unused Services: Identify all active software components (such as PaperCut, Kestra, Cua server, or AutoAgent tools) and ensure they are not unnecessarily exposed to the network or the internet with default settings.
- Credential Revocation and Rotation: In light of recent incidents such as the one associated with JetBrains Cadence, urgently rotate all secrets and access keys (such as API, AWS, etc.) that might have been exposed in test environments or affected CI/CD platforms.
- Rigorous Log Monitoring: Monitor access logs (especially on login routes, API endpoints, and active web-exposed log files) to detect potential exploitation attempts early.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




