Weekly Exploit Roundup 2026-09-08
Weekly Exploit Roundup
Generated 2026-09-08T08:00:10.982095+00:00 (UTC)
- Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
Source: Rapid7 Cybersecurity Blog | Published: 2026-09-02T16:58:45+00:00 | Score: 25.981Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path. CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions. Although, by leveraging the SSRF vulnerability CVE-2026-83548 an attacker could potentially exploit CVE-2026-83549
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Source: The Hacker News | Published: 2026-09-04T07:18:47+00:00 | Score: 24.722Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Source: The Hacker News | Published: 2026-09-02T07:08:50+00:00 | Score: 19.289Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.
The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog
Source: Alerts | Published: 2026-09-02T12:00:00+00:00 | Score: 18.833CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
Source: The Hacker News | Published: 2026-09-07T11:20:14+00:00 | Score: 17.785A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.
Security firm TantoSec has published a working exploit chain targeting vulnerabilities
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Source: The Hacker News | Published: 2026-09-04T08:48:45+00:00 | Score: 17.767Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
The vulnerabilities in question are –
CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Source: BleepingComputer | Published: 2026-09-07T16:50:29+00:00 | Score: 17.749A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. […]
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Source: The Hacker News | Published: 2026-09-05T20:14:47+00:00 | Score: 17.322Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
- Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Source: SecurityWeek | Published: 2026-09-07T11:58:37+00:00 | Score: 15.904The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek .
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Source: The Hacker News | Published: 2026-09-02T07:47:13+00:00 | Score: 15.808Forescout Research – Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.
The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
End of report.