● Daily security briefing
Thursday, September 3, 2026
September 3rd saw moderate advisory activity with 165 CERT/PSIRT notices and 2,654 CVEs published, though no KEV additions. Critical vulnerabilities dominated the landscape, including multiple CVSS 10.0 flaws in SiYuan affecting SQL query execution and search functions in publish mode, alongside critical issues in MapLibre GL JS, D-Link DNS-340L, and TOTOLINK CP450 routers. Notable CERT-BUND advisories flagged JFrog Artifactory (allowing admin privilege escalation), LiteLLM, and Linux Kernel vulnerabilities as exploited in the wild, while CISA highlighted critical flaws in industrial control systems including Rockwell Automation ArmorStart LT and ControlFLASH, Pyramid Solutions NetStaX, IXON VPN Client, and Tycon Systems TPDIN-Monitor-WEB3. Additional CVSS 9.8-9.9 critical flaws emerged in unauthenticated PHP object injection vulnerabilities affecting JobSearch and Mail Mint plugins.
22 critical1 high1 mediumacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- mediumexploitedcert-bund[NEW] [medium] Linux Kernel: Multiple vulnerabilities
- highexploitedcert-bund[NEW] [high] LiteLLM: Multiple vulnerabilities
- criticalexploitedcert-bund[NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privileges
- criticalcisaPyramid Solutions NetStaX EtherNet/IP Stack
- criticalcisaRockwell Automation ArmorStart LT
- criticalcisaRockwell Automation ControlFLASH
- criticalcisaIXON VPN Client
- criticalcisaTycon Systems TPDIN-Monitor-WEB3
- criticalcisaOPCFoundation OPC UA LocalDiscoveryServer (LDS)
- criticalcisaInductive Automation Ignition
- criticalcisaRockwell Automation 1756-ENBT Module
- criticalcisaSchneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-69084CVSS 10GHSA-vh22-h7hf-www7: SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
- criticalCVE-2026-72811CVSS 10GHSA-q2vg-7qgx-x5fc: SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
- criticalCVE-2026-69083CVSS 10GHSA-fph3-ghq9-vw66: SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
- criticalCVE-2026-85061CVSS 10MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while r
- criticalCVE-2026-85223CVSS 9.9A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing
- criticalCVE-2026-85031CVSS 9.9A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl
- criticalCVE-2026-84834CVSS 9.8Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
- criticalCVE-2026-84753CVSS 9.8Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- criticalCVE-2026-82526CVSS 9.8R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter
- criticalCVE-2026-85391CVSS 9.8Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can
- criticalCVE-2026-84814CVSS 9.8Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- criticalCVE-2026-84238CVSS 9.8Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 165 above.