Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Sunday, 30 August 2026

🛡️ Cyber Times — CISO Intelligence Update

Sunday, 30 August 2026 · Coverage: 29 Aug 2026 08:00 IST → 30 Aug 2026 08:00 IST

The high-confidence sweep produced 30 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.

🛡️ Vulnerabilities Worth Attention

CVE-2026-82456 — argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is…

CRITICAL — NVD CVSS 10.0 (critical). argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator’s stored token to create applications, request syncs, and modify Argo CD resources.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 19:46 IST Sources: NVD

CVE-2026-15369 — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3

CRITICAL — NVD CVSS 9.8 (critical). The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg_checkout_data_to_order_meta_data_block() function, persisting…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 01:46 IST Sources: NVD

CVE-2026-14494 — The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function

CRITICAL — NVD CVSS 9.8 (critical). The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. This makes it possible for…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 17:46 IST Sources: NVD

CVE-2026-16259 — The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the…

CRITICAL — NVD CVSS 9.8 (critical). The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator’s email and…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 11:47 IST Sources: NVD

CVE-2026-82466 — Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account

CRITICAL — NVD CVSS 9.4 (critical). Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 22:47 IST Sources: NVD

CVE-2026-82460 — Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path…

CRITICAL — NVD CVSS 9.3 (critical). Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 22:47 IST Sources: NVD

CVE-2026-82454 — The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification

CRITICAL — NVD CVSS 9.3 (critical). The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the ‘alg’ field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 29 Aug 2026 19:46 IST Sources: NVD

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 538 records inspected · 78 passed collection filters · 30 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Monday, 31 August 2026
Next Post
CISO Intelligence Update — Saturday, 29 August 2026