Wednesday, September 2, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Hewlett Packard Enterprise leads the day's disclosures with two maximum-severity flaws in Fabric Composer (CVE-2026-76657 and CVE-2026-76658, both CVSS 10) alongside a CVSS 9.8 issue in AOS-CX network switches. Critical CVEs fell 36% to 28 from the prior day's 44, while high-priority CVEs rose 31% to 105, for a total of 133 disclosed vulnerabilities. Other notable critical entries include CVE-2026-84119 and CVE-2026-84121 affecting Mozilla Firefox and Thunderbird (CVSS 9.6), CVE-2026-84372 in the Predis PHP Redis client (CVSS 9.8), and CVE-2026-84480 in the WWBN AVideo platform (CVSS 9.8). Network management, browser, and WordPress plugin ecosystems account for much of the critical volume, with SigmaForms Pro and the Amelia booking plugin both carrying CVSS 9.8 ratings. Nine CVEs have confirmed active exploitation, including PaperCut MF/NG and JFrog Artifactory; with patch availability at 0% across the set, teams should verify vendor advisories directly and prioritize compensating controls for exposed systems.

  • HPE Fabric Composer has two CVSS 10 vulnerabilities (CVE-2026-76657, CVE-2026-76658), with a further CVSS 9.8 flaw in AOS-CX switches
  • 28 critical CVEs disclosed, down 36% from 44 the prior day
  • 105 high-priority CVEs disclosed, up 31% from 80 the prior day
  • Mozilla Firefox and Thunderbird carry two CVSS 9.6 flaws (CVE-2026-84119, CVE-2026-84121); Predis and WWBN AVideo each have CVSS 9.8 issues exposing remote code execution risk
  • Patch availability is 0% across the set; affected systems include HPE network management, Mozilla browsers and mail clients, Predis-backed PHP applications, and WordPress plugins SigmaForms Pro and Amelia
  • 9 CVEs show active exploitation, including PaperCut MF/NG (two flaws), JFrog Artifactory, ownCloud Core, and the Linux kernel

Immediate action: Prioritize HPE Fabric Composer and AOS-CX deployments, Mozilla Firefox and Thunderbird installations, and internet-facing PaperCut MF/NG and JFrog Artifactory instances given confirmed exploitation. Patch availability is reported at 0% for this set, so check vendor advisories directly for fixes released since disclosure and restrict network access to affected management interfaces until updates are applied.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation