CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Thursday, September 3, 2026

September 3rd saw moderate advisory activity with 165 CERT/PSIRT notices and 2,654 CVEs published, though no KEV additions. Critical vulnerabilities dominated the landscape, including multiple CVSS 10.0 flaws in SiYuan affecting SQL query execution and search functions in publish mode, alongside critical issues in MapLibre GL JS, D-Link DNS-340L, and TOTOLINK CP450 routers. Notable CERT-BUND advisories flagged JFrog Artifactory (allowing admin privilege escalation), LiteLLM, and Linux Kernel vulnerabilities as exploited in the wild, while CISA highlighted critical flaws in industrial control systems including Rockwell Automation ArmorStart LT and ControlFLASH, Pyramid Solutions NetStaX, IXON VPN Client, and Tycon Systems TPDIN-Monitor-WEB3. Additional CVSS 9.8-9.9 critical flaws emerged in unauthenticated PHP object injection vulnerabilities affecting JobSearch and Mail Mint plugins.

Last updated 22:40 UTC

CERT / PSIRT advisories
165
CVEs published
2654
Added to KEV
0
Known exploited
3

22 critical1 high1 mediumacross the day’s notable advisories and CVEs

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 165 above.

plus 352 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.