🛡️ Cyber Times — CISO Intelligence Update
Thursday, 03 September 2026 · Coverage: 02 Sep 2026 08:00 IST → 03 Sep 2026 08:00 IST
The high-confidence sweep produced 39 publishable records. This edition presents 14 source-linked updates across 3 security domains; 12 are marked for priority review.
🔴 Critical Threats & Active Exploitation
CVE-2026-9586 added to CISA KEV — Sangoma Switchvox
CRITICAL — Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 03 Sep 2026 02:30 IST Sources: CISA KEV · The Hacker News · BleepingComputer · Help Net Security
CVE-2026-82329 added to CISA KEV — JFrog Artifactory
CRITICAL — JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 02 Sep 2026 21:17 IST Sources: CISA KEV · BleepingComputer
CVE-2026-83548 added to CISA KEV — SonicWall SMA1000 Appliances
CRITICAL — SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 02 Sep 2026 16:23 IST Sources: CISA KEV · The Hacker News
CVE-2026-59822 added to CISA KEV — BerriAI LiteLLM
CRITICAL — BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 02 Sep 2026 05:30 IST Sources: CISA KEV
CVE-2026-48710 added to CISA KEV — Kludex Starlette
CRITICAL — Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271. Required action: Apply mitigations in accordance with vendor instructions, ensuring…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 02 Sep 2026 05:30 IST Sources: CISA KEV
🛡️ Vulnerabilities Worth Attention
CVE-2026-4357 — The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it…
CRITICAL — NVD CVSS 10.0 (critical). The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 20:47 IST Sources: NVD
CVE-2026-77009 — The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any…
CRITICAL — NVD CVSS 9.9 (critical). The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 20:47 IST Sources: NVD
CVE-2026-19117 — Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user
CRITICAL — NVD CVSS 9.8 (critical). Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 03 Sep 2026 00:47 IST Sources: NVD
CVE-2026-20279 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive…
CRITICAL — NVD CVSS 9.8 (critical). As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 22:47 IST Sources: NVD
CVE-2026-20274 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive…
CRITICAL — NVD CVSS 9.8 (critical). As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 22:47 IST Sources: NVD
CVE-2026-20212 — A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root…
CRITICAL — NVD CVSS 9.8 (critical). A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 22:47 IST Sources: NVD
CVE-2026-53611 — Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping /…
CRITICAL — NVD CVSS 9.8 (critical). Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 21:47 IST Sources: NVD
🧪 Threat Intelligence & Attack Research
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
INFORMATIONAL — Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42 .
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 02 Sep 2026 15:30 IST Sources: Palo Alto Unit 42
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
INFORMATIONAL — Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat…
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 03 Sep 2026 04:21 IST Sources: Microsoft Security
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,619 records inspected · 152 passed collection filters · 39 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.