🛡️ Cyber Times — CISO Intelligence Update
Sunday, 06 September 2026 · Coverage: 05 Sep 2026 08:00 IST → 06 Sep 2026 08:00 IST
The high-confidence sweep produced 30 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-86152 — A flaw has been found in Tenda CP3 27.5.57.101
CRITICAL — NVD CVSS 10.0 (critical). A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 06 Sep 2026 07:47 IST Sources: NVD
CVE-2026-86153 — A vulnerability has been found in Tenda CP3 27.5.57.101
CRITICAL — NVD CVSS 9.4 (critical). A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 06 Sep 2026 07:47 IST Sources: NVD
CVE-2026-86151 — A vulnerability was detected in Tenda CP3 27.5.57.101
CRITICAL — NVD CVSS 9.4 (critical). A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 06 Sep 2026 05:46 IST Sources: NVD
CVE-2026-86149 — A weakness has been identified in Tenda CP3 27.5.57.101
CRITICAL — NVD CVSS 9.4 (critical). A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 06 Sep 2026 03:47 IST Sources: NVD
CVE-2026-86148 — A security flaw has been discovered in Tenda CP3 27.5.57.101
CRITICAL — NVD CVSS 9.4 (critical). A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 06 Sep 2026 03:47 IST Sources: NVD
CVE-2026-86123 — SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against…
CRITICAL — NVD CVSS 9.4 (critical). SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server’s network without authentication.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 05 Sep 2026 15:46 IST Sources: NVD
CVE-2026-10196 — The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
CRITICAL — NVD CVSS 9.8 (critical). The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the ‘handle_form_submission’ function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 05 Sep 2026 17:46 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 626 records inspected · 99 passed collection filters · 30 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.