Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Tuesday, 01 September 2026

🛡️ Cyber Times — CISO Intelligence Update

Tuesday, 01 September 2026 · Coverage: 31 Aug 2026 08:00 IST → 01 Sep 2026 08:00 IST

The high-confidence sweep produced 34 publishable records. This edition presents 9 source-linked updates across 2 security domains; 9 are marked for priority review.

🔴 Critical Threats & Active Exploitation

CVE-2026-82078 added to CISA KEV — PaperCut NG/MF

CRITICAL — PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 31 Aug 2026 05:30 IST Sources: CISA KEV

CVE-2026-81578 added to CISA KEV — PaperCut NG/MF

CRITICAL — PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 31 Aug 2026 05:30 IST Sources: CISA KEV

🛡️ Vulnerabilities Worth Attention

CVE-2026-81780 — Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

CRITICAL — NVD CVSS 10.0 (critical). Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 01 Sep 2026 02:47 IST Sources: NVD

CVE-2026-81779 — Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted

CRITICAL — NVD CVSS 10.0 (critical). Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 01 Sep 2026 02:47 IST Sources: NVD

CRITICAL — NVD CVSS 10.0 (critical). Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 31 Aug 2026 20:48 IST Sources: NVD

CVE-2026-79748 — MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

CRITICAL — NVD CVSS 9.9 (critical). MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 31 Aug 2026 23:47 IST Sources: NVD

CVE-2026-82226 — Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 01 Sep 2026 02:47 IST Sources: NVD

CVE-2026-58574 — Dell PowerStore contains a Missing Authentication for Critical Function vulnerability

CRITICAL — NVD CVSS 9.8 (critical). Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 31 Aug 2026 12:47 IST Sources: NVD

CVE-2026-53552 — Goploy is an open-source automation deployment system

CRITICAL — NVD CVSS 9.6 (critical). Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller’s namespace. The corresponding model.ProjectFile.GetData and…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 01 Sep 2026 00:46 IST Sources: NVD

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 2,626 records inspected · 133 passed collection filters · 34 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Wednesday, 02 September 2026
Next Post
CISO Intelligence Update — Monday, 31 August 2026