Today, September 8, 2026, the CyberSec Intelligence analysis team presents the summary of security vulnerabilities with a major impact on IT infrastructures. This bulletin details the actively exploited vulnerabilities currently and the newly reported critical breaches, providing practical recommendations for protecting organizational assets.
Actively Exploited Vulnerabilities
- CVE-2026-85046 (Google Chromium V8): A “type confusion” vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a modified HTML page. Details: NVD CVE-2026-85046.
- CVE-2026-59822 (BerriAI LiteLLM): Improper authentication in the MCP Streamable HTTP endpoint, allowing unauthenticated attackers to establish sessions using arbitrary tokens. Details: NVD CVE-2026-59822.
- CVE-2026-48710 (Kludex Starlette): HTTP request/response smuggling vulnerability that can be used to bypass authentication by injecting paths into the host section. Details: NVD CVE-2026-48710.
- CVE-2026-49869 (Kestra Kestra OSS): OS command injection, allowing an unauthenticated attacker to create and run arbitrary workflows. Details: NVD CVE-2026-49869.
- CVE-2026-82329 (JFrog Artifactory): An authentication error in default configurations that allows a network attacker to obtain administrative privileges. Details: NVD CVE-2026-82329.
- CVE-2026-9586 (Sangoma Switchvox): SQL injection in the backend PostgreSQL database, allowing the execution of arbitrary SQL commands and remote code execution. Details: NVD CVE-2026-9586.
- CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA1000): The first represents an SSRF vulnerability that provides unauthorized access to sensitive functions, and the second is an OS command injection that allows authenticated administrators to execute arbitrary code. Details: CVE-2026-83548 and CVE-2026-83549.
New Critical Vulnerabilities
- CVE-2026-86167: Command injection in the formgponConf function of the Boa component on Tenda HG10 devices, exposing the device to remote command execution. Details: NVD CVE-2026-86167.
- CVE-2026-79697 and CVE-2026-79698: Command injections in Advantech WISE-6610 gateways, affecting the basicstation_apply and nodered_lib_apply functions. Remediation is achieved by upgrading to version 1.2.4_20260821. Details: CVE-2026-79697 and CVE-2026-79698.
- CVE-2026-86296: Stack-based buffer overflow in the udhcpcd component of D-Link DIR-822A routers, exploitable remotely. Details: NVD CVE-2026-86296.
- CVE-2026-86299: OS command injection in the PingTest module of Linksys RE7000 devices. Details: NVD CVE-2026-86299.
- CVE-2026-6223: Authentication bypass in the BiHayat App of Bahçelievler Municipality due to the lack of rate limiting on login attempts. Details: NVD CVE-2026-6223.
- CVE-2026-76578: OTP token vulnerability in FreeIPA, allowing an unauthenticated LDAP client to create an arbitrary Kerberos principal and add it to the administrators group. Details: NVD CVE-2026-76578.
- CVE-2026-7861: Unsafe deserialization in the Next4Biz CSM platform, allowing code injection. Details: NVD CVE-2026-7861.
- CVE-2026-75650: Improper neutralization in the Adobe Commerce template engine, facilitating arbitrary code execution without user interaction. Details: NVD CVE-2026-75650.
- CVE-2026-86542 and CVE-2026-86543 (knowns): The first allows import directory traversal and file overwriting, and the second exposes the management API without authentication on all network interfaces. Details: CVE-2026-86542 and CVE-2026-86543.
- CVE-2026-44756: Memory safety vulnerability in the EPP (Extended Passport Protocol) processing library that can lead to the compromise of application confidentiality, integrity, and availability. Details: NVD CVE-2026-44756.
From the Security Press
- Telerik UI Padding-Oracle Bug: A public proof-of-concept exploit demonstrates how a padding oracle vulnerability in Telerik UI for ASP.NET AJAX can be turned into remote code execution (RCE), targeting applications in a specific non-default configuration. Source: The Hacker News.
- N-able N-central Hotfix: The N-able company has released its fourth security hotfix in the last five weeks for the N-central platform, correcting a critical unauthenticated RCE vulnerability affecting on-premises versions below build 2026.3.1.14. Source: The Hacker News.
What we recommend
- Rigorous patch management: Urgently apply security updates for exposed products, especially for Google Chromium, N-able N-central (to Hotfix 4), Adobe Commerce, and FreeIPA.
- IoT device inventory and security: Identify all active Tenda, D-Link routers, and Advantech gateways in your networks and limit their direct exposure to the public internet.
- Correct authentication configuration: Change default passwords and settings of platforms like JFrog Artifactory or Kestra and ensure that management APIs are not publicly exposed without strong credentials.
- Continuous traffic monitoring: Implement detection rules at the IPS/IDS systems level to block command injection attempts, SQL injection, or “smuggling” attacks.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




