Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Friday, 04 September 2026

🛡️ Cyber Times — CISO Intelligence Update

Friday, 04 September 2026 · Coverage: 03 Sep 2026 08:00 IST → 04 Sep 2026 08:00 IST

The high-confidence sweep produced 34 publishable records. This edition presents 8 source-linked updates across 2 security domains; 7 are marked for priority review.

🛡️ Vulnerabilities Worth Attention

CVE-2026-83711 — Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CRITICAL — NVD CVSS 10.0 (critical). Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 04:47 IST Sources: NVD

CVE-2026-70352 — Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CRITICAL — NVD CVSS 10.0 (critical). Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 04:47 IST Sources: NVD

CVE-2026-85061 — MapLibre GL JS is an interactive vector tile map library for web browsers

CRITICAL — NVD CVSS 10.0 (critical). MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 02:47 IST Sources: NVD

CVE-2026-85050 — Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a…

CRITICAL — NVD CVSS 9.6 (critical). Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD

CVE-2026-85047 — Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary…

CRITICAL — NVD CVSS 9.6 (critical). Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD

CVE-2026-85042 — Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

CRITICAL — NVD CVSS 9.6 (critical). Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 01:47 IST Sources: NVD

CVE-2026-84834 — Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 03 Sep 2026 22:47 IST Sources: NVD

🌐 Industry, Brand & Internet Security

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

INFORMATIONAL — Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.

Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.

Validation: direct source · Published: 04 Sep 2026 02:33 IST Sources: Cloudflare Security

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 1,034 records inspected · 131 passed collection filters · 34 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Saturday, 05 September 2026
Next Post
CISO Intelligence Update — Thursday, 03 September 2026