Thursday, September 3, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Cisco network infrastructure leads the disclosures from yesterday, with CVE-2026-20274 and CVE-2026-20279 in IOS XR Software and CVE-2026-20212 in NX-OS Software all rated CVSS 9.8. Twenty critical CVEs were disclosed, a 29% decrease from the prior day, along with 60 high-priority CVEs, down 43%. Other critical issues include CVE-2026-4357 (CVSS 10) in the WordPress Embed HTML5 Game plugin, CVE-2026-85031 (CVSS 9.9) in the TOTOLINK CP450 router, and CVE-2026-66786 (CVSS 9.1) in Red Hat Advanced Cluster Management for Kubernetes. Network devices, WordPress plugins, and container orchestration platforms account for most of the critical activity, with 10 CVEs under active exploitation spanning SonicWall SMA1000, JFrog Artifactory, PaperCut MF/NG, Kestra, and LiteLLM. No patch availability data is confirmed for the day's disclosures, so teams should check vendor advisories directly and apply compensating controls where fixes are not yet published.

  • Cisco IOS XR (CVE-2026-20274, CVE-2026-20279) and NX-OS (CVE-2026-20212) carry CVSS 9.8 ratings affecting core network infrastructure
  • 20 critical CVEs disclosed, down 29% from the prior day's 28
  • 60 high-priority CVEs disclosed, down 43% from 105
  • CVE-2026-4357 (CVSS 10) in the WordPress Embed HTML5 Game plugin and CVE-2026-85031 (CVSS 9.9) in TOTOLINK CP450 routers expose internet-facing systems
  • Patch availability is 0% confirmed across the disclosures; verify vendor advisories for Cisco, Red Hat, and TOTOLINK directly
  • 10 CVEs under active exploitation, including SonicWall SMA1000 (CVE-2026-83548, CVSS 10), JFrog Artifactory, and PaperCut MF/NG

Immediate action: Prioritize Cisco IOS XR and NX-OS devices, SonicWall SMA1000 appliances, JFrog Artifactory, and PaperCut MF/NG servers, since these combine high severity with confirmed exploitation or broad network exposure. Patch availability is unconfirmed for the critical disclosures, so consult vendor advisories now, restrict management interface exposure, and monitor for exploitation indicators until fixes are applied.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation