⌁ DAY 41UNDERCOVERED IN US

CISA adds four critical vulnerabilities to known exploited catalog

CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8 that allows remote code execution via crafted HTML, to its Known Exploited Vulnerabilities catalog as of September 4, 2026. The catalog simultaneously tracked four other critical flaws in LiteLLM, Starlette, Kestra, and SonicWall appliances.

10 reports · 9 independentprimary · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-59822: BerriAI LiteLLM — BerriAI LiteLLM Improper Authentication Vulnerability

json:cisa-kevprimary27d ago kagi ↗

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidanc

CVE-2026-48710: Kludex Starlette — Kludex Starlette HTTP Request/Response Smuggling Vulnerability

json:cisa-kevprimary27d ago kagi ↗

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271. Action: Apply mitigations in accordance with vendor instructions, e

CVE-2026-49869: Kestra Kestra OSS — Kestra OSS OS Command Injection Vulnerability

json:cisa-kevprimary27d ago kagi ↗

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see

CVE-2026-82329: JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability

json:cisa-kevprimary27d ago kagi ↗

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Tr

CVE-2026-9586: Sangoma Switchvox — Sangoma Switchvox SQL Injection Vulnerability

json:cisa-kevprimary27d ago kagi ↗

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security

CVE-2026-83548: SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

json:cisa-kevprimary27d ago kagi ↗

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guid

CVE-2026-83549: SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances OS Command Injection Vulnerability

json:cisa-kevprimary27d ago kagi ↗

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CIS

CVE-2026-85046: Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

json:cisa-kevprimary25d ago kagi ↗

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with

CISA Adds One Known Exploited Vulnerability to Catalog

rss:cisa-advisoriesprimary25d ago kagi ↗

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security U

🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0904 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother25d ago kagi ↗

🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0904 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder