Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Saturday, 05 September 2026

🛡️ Cyber Times — CISO Intelligence Update

Saturday, 05 September 2026 · Coverage: 04 Sep 2026 08:00 IST → 05 Sep 2026 08:00 IST

The high-confidence sweep produced 32 publishable records. This edition presents 9 source-linked updates across 3 security domains; 8 are marked for priority review.

🔴 Critical Threats & Active Exploitation

CVE-2026-85046 added to CISA KEV — Google Chromium V8

CRITICAL — Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 05 Sep 2026 04:20 IST Sources: CISA KEV · Security Affairs · The Hacker News · Help Net Security

🛡️ Vulnerabilities Worth Attention

CVE-2026-85696 — SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without…

CRITICAL — NVD CVSS 9.3 (critical). SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 23:50 IST Sources: NVD · systemtek.co.uk

CVE-2026-75754 — Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized…

CRITICAL — NVD CVSS 10.0 (critical). Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 08:47 IST Sources: NVD

CVE-2026-75430 — PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port

CRITICAL — NVD CVSS 9.8 (critical). PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 22:46 IST Sources: NVD

CVE-2026-31020 — In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions

CRITICAL — NVD CVSS 9.8 (critical). In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI)…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 22:46 IST Sources: NVD

CVE-2026-18658 — IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection

CRITICAL — NVD CVSS 9.8 (critical). IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 21:47 IST Sources: NVD

CVE-2026-82923 — The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated…

CRITICAL — NVD CVSS 9.8 (critical). The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 15:47 IST Sources: NVD

CVE-2026-15354 — The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66

CRITICAL — NVD CVSS 9.8 (critical). The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the submit() function, which allows unauthenticated form submissions to control the target user ID before calling wp_update_user(). This makes it possible for unauthenticated attackers to overwrite any WordPress user’s email…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 04 Sep 2026 12:47 IST Sources: NVD

🧪 Threat Intelligence & Attack Research

How to secure edge AI in customer-owned environments

INFORMATIONAL — As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog .

Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.

Validation: direct source · Published: 05 Sep 2026 00:40 IST Sources: Microsoft Security

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 2,861 records inspected · 133 passed collection filters · 32 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Sunday, 06 September 2026
Next Post
CISO Intelligence Update — Friday, 04 September 2026