Tuesday, September 1, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Google Chrome, D-Link ShareCenter NAS, and a set of embedded network appliances account for the highest-impact disclosures, with remote code execution and authentication bypass the dominant patterns. The day brought 44 critical CVEs (CVSS 9.0 and above), up 69% from the prior day's 26, alongside 80 high-priority issues, a 19% increase from 67. Named critical entries include CVE-2026-82971 (CVSS 10, QVidium Opera11), CVE-2026-83524 (CVSS 9.9, RedPort Optimizer wXa series), and CVE-2026-82692 (CVSS 9.9, D-Link DNS-340L and DNS-345 ShareCenter), with CVE-2026-78948 and CVE-2026-78904 (both CVSS 9.6) affecting Google Chrome. Edge and IoT devices, WordPress plugins (WPLP Cookie Consent, Tickera), and enterprise infrastructure such as NetScaler ADC, JFrog Artifactory, and PaperCut MF/NG make up the bulk of exposure, and 11 entries carry confirmed active exploitation. No vendor patch links were confirmed for the newly disclosed set at publication time (0% patch availability), so treat mitigation and network-level restriction as the near-term posture while monitoring vendor advisories.

  • Google Chrome carries two critical browser flaws (CVE-2026-78948 and CVE-2026-78904, both CVSS 9.6), with wide desktop and mobile exposure
  • 44 critical CVEs (CVSS 9.0+), up 69% from 26 the prior day
  • 80 high-priority CVEs (CVSS 7.0-8.9), up 19% from 67 the prior day
  • Remote code execution and authentication bypass dominate, affecting QVidium Opera11 (CVSS 10), RedPort Optimizer wXa-203/213/223 (CVSS 9.9), D-Link DNS-340L and DNS-345 ShareCenter (CVSS 9.9), and Ebyte NA111-M firmware (CVSS 9.8)
  • Patch availability is 0% for the disclosed set, leaving embedded network gear (ZTE ZXDU68, Ebyte, RedPort) and WordPress plugins without confirmed fixes
  • 11 CVEs have confirmed active exploitation, including NetScaler ADC and Gateway, JFrog Artifactory, PaperCut MF/NG, and the Linux kernel

Immediate action: Prioritize Google Chrome updates across the fleet, then internet-facing infrastructure running NetScaler ADC and Gateway, JFrog Artifactory, and PaperCut MF/NG, all of which appear on the actively exploited list. Embedded and edge devices (QVidium, RedPort Optimizer, D-Link ShareCenter, Ebyte, ZTE) have no confirmed patches yet, so restrict management interfaces to trusted networks and monitor vendor advisories for fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation