Saturday, September 5, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Friday's disclosures were led by remote code execution flaws in Google Chrome, Mozilla Firefox and Thunderbird, alongside a cluster of critical WordPress plugin vulnerabilities and two IBM enterprise products. Critical CVEs fell 44% from the prior day to 29, while high-priority CVEs dropped 14% to 67, for 96 total. Notable entries include CVE-2026-84129 (CVSS 9.8) affecting Mozilla Firefox and Thunderbird, CVE-2026-84354 (CVSS 9.6) in Google Chrome, and CVE-2026-18658 (CVSS 9.8) in IBM Operational Decision Manager. WordPress plugins account for four of the top critical CVEs, including Hummingbird Performance and MStore API, and 10 CVEs have confirmed active exploitation, spanning SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, LiteLLM and Starlette. Prioritize internet-facing edge appliances and print management servers with confirmed exploitation, push browser updates across the fleet, and confirm fix status for each affected product in the vendor advisory.

  • Google Chrome, Mozilla Firefox and Thunderbird carry critical CVSS 9.0 to 9.8 flaws, with one Chrome bug (CVE-2026-85046) under active exploitation
  • 29 critical CVEs, down 44% from 52 the prior day
  • 67 high-priority CVEs, down 14% from 78 the prior day
  • Remote code execution dominates: WordPress plugins (Hummingbird Performance, AI Website Builder, ComboBlocks, MStore API), IBM Operational Decision Manager and IBM Instana Agent
  • Check SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, Sangoma Switchvox, LiteLLM and Starlette deployments first, all with confirmed exploitation
  • 10 CVEs are actively exploited, up one from the prior day

Immediate action: Patch or isolate SonicWall SMA1000 appliances, PaperCut MF/NG servers, JFrog Artifactory and Kestra instances immediately given confirmed active exploitation, then roll out Chrome, Firefox and Thunderbird updates across managed endpoints. Audit WordPress sites for the affected plugins and review IBM ODM and Instana Agent exposure. Confirm fix status for each product in the vendor advisory before closing tickets.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation