The CyberSec Intelligence team presents its daily security bulletin for 5 September 2026. We review actively exploited vulnerabilities in the CISA KEV catalogue, new critical NVD entries and recent reporting from the international security press.
Actively exploited vulnerabilities
- CVE-2026-85046 (Google Chromium V8) – Type confusion allowing remote arbitrary code execution inside the sandbox through a crafted HTML page.
- CVE-2026-59822 (BerriAI LiteLLM) – Improper authentication in the HTTP MCP Streamable endpoint allows an unauthenticated attacker to establish a valid session with an arbitrary Bearer token.
- CVE-2026-48710 (Kludex Starlette) – HTTP request/response smuggling can inject host paths and bypass URL-reconstruction authentication.
- CVE-2026-49869 (Kestra OSS) – Unauthenticated OS command injection allows arbitrary workflows to be created and executed.
- CVE-2026-82329 (JFrog Artifactory) – A default authentication weakness can grant administrative privileges to an unauthenticated network attacker.
- CVE-2026-9586 (Sangoma Switchvox) – Unauthenticated remote SQL injection may lead to arbitrary SQL commands and remote code execution.
- CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000) – SSRF and administrator-level OS command injection expose sensitive appliance functions.
- CVE-2026-82078 / CVE-2026-81578 (PaperCut NG/MF) – Unsafe reflection and missing authentication allow configuration changes and arbitrary Java bytecode execution.
Critical new vulnerabilities
New high-impact entries include a buffer overflow in TOTOLINK CP450, insecure socket.io configuration in Taipy, asymmetric-key validation flaws in python-jose, authentication bypasses in MOOS components, WordPress Divi local file inclusion, path confinement issues in excel-mcp-server, webhook validation flaws and multiple unauthenticated file or command injection issues.
What to do
Prioritise patches for internet-facing systems, review exposure to the affected products and monitor authentication and administrative activity. A vulnerability that is only “on the list” is still a problem if the system is reachable and forgotten.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.



