● Daily security briefing
Wednesday, September 2, 2026
September 2nd saw elevated advisory activity with 193 CERT/PSIRT advisories and 2,041 CVEs published, including seven vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog: JFrog Artifactory, Kestra OSS, BerriAI LiteLLM, Kludex Starlette, Sangoma Switchvox, and two SonicWall SMA1000 flaws covering authentication bypass, command injection, and SSRF. Multiple critical advisories dominated the day, particularly around actively exploited browser vulnerabilities in Chrome and Edge, and new critical issues in SonicWall SMA appliances and JFrog Artifactory allowing privilege escalation. Beyond KEV additions, several critical CVEs emerged including WordPress plugin flaws (CVE-2026-4357, CVE-2026-77009), Craft CMS pre-authentication user registration bypass (CVE-2026-84795), Cisco IOS XR and Nexus switch vulnerabilities (CVE-2026-20279, CVE-2026-20212), and SeaweedFS unauthenticated S3 administrative access (GHSA-2v6v-25fm-p4fg), all rated at CVSS 9.8 or higher.
14 critical8 high2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-82329CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability
- exploitedCVE-2026-49869CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
- exploitedCVE-2026-59822CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability
- exploitedCVE-2026-48710CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- exploitedCVE-2026-9586CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability
- exploitedCVE-2026-83548CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- exploitedCVE-2026-83549CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcert-bund[UPDATE] [high] Google Chrome and Microsoft Edge: Multiple Vulnerabilities enable code execution
- highexploitedcert-bund[UPDATE] [high] Google Chrome / Microsoft Edge: Multiple Vulnerabilities
- criticalexploitedcert-bund[NEW] [critical] SonicWall SMA: Multiple vulnerabilities
- highexploitedcert-bund[UPDATE] [high] Google Chrome / Microsoft Edge: Vulnerability enables code execution
- highexploitedcert-bund[UPDATE] [high] Google Chrome and Microsoft Edge: Multiple Vulnerabilities
- criticalexploitedcert-bund[NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privileges
- highexploitedcisaCISA Adds Seven Known Exploited Vulnerabilities to Catalog
- unknownexploitedcccsJFrog security advisory (AV26-867) – Update 1
- highexploitedcert-bund[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnerabilities
- highexploitedcert-bund[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Multiple vulnerabilities
- unknownexploitedcccsSonicWall security advisory (AV26-872) – Update 1
- highexploitedcert-bund[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-4357CVSS 10The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenti
- criticalCVE-2026-77009CVSS 9.9The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as
- criticalCVE-2026-84795CVSS 9.8Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivate
- criticalCVE-2026-20279CVSS 9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
- criticalCVE-2026-72920CVSS 9.8GHSA-2v6v-25fm-p4fg: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
- criticalCVE-2026-20212CVSS 9.8A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. Th
- criticalCVE-2026-53611CVSS 9.8Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP loo
- criticalCVE-2026-19117CVSS 9.8Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premi
- criticalCVE-2026-81294CVSS 9.8Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- criticalCVE-2025-9314CVSS 9.8The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
- criticalCVE-2026-20274CVSS 9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
- criticalCVE-2026-78657CVSS 9.8The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files functi
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 193 above.