🛡️ Cyber Times — CISO Intelligence Update
Friday, 04 September 2026 · Coverage: 03 Sep 2026 08:00 IST → 04 Sep 2026 08:00 IST
The high-confidence sweep produced 34 publishable records. This edition presents 8 source-linked updates across 2 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-83711 — Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CRITICAL — NVD CVSS 10.0 (critical). Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 04:47 IST Sources: NVD
CVE-2026-70352 — Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
CRITICAL — NVD CVSS 10.0 (critical). Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 04:47 IST Sources: NVD
CVE-2026-85061 — MapLibre GL JS is an interactive vector tile map library for web browsers
CRITICAL — NVD CVSS 10.0 (critical). MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 02:47 IST Sources: NVD
CVE-2026-85050 — Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a…
CRITICAL — NVD CVSS 9.6 (critical). Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD
CVE-2026-85047 — Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary…
CRITICAL — NVD CVSS 9.6 (critical). Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD
CVE-2026-85042 — Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page
CRITICAL — NVD CVSS 9.6 (critical). Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD
CVE-2026-84834 — Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 03 Sep 2026 22:47 IST Sources: NVD
🌐 Industry, Brand & Internet Security
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
INFORMATIONAL — Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 04 Sep 2026 02:33 IST Sources: Cloudflare Security
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 1,034 records inspected · 131 passed collection filters · 34 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.