Friday, September 4, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures were led by three Google Chrome vulnerabilities rated CVSS 9.6, a cluster of CVSS 9.8 flaws in the themoos core-moos framework, and critical issues in WordPress plugins from Divi Engine and WPFunnels. Critical CVEs reached 52, up 160% from the prior day's 20, while high-priority CVEs rose 30% to 78. Notable entries include CVE-2026-85042 in Google Chrome, CVE-2026-11613 in the Divi Ajax Filter plugin, CVE-2026-85181 in Dianping CAT, and CVE-2026-85216 in the MISP threat intelligence platform. Browser memory safety bugs, WordPress plugin input handling flaws, and open-source framework weaknesses dominate the set, with additional exposure for security tooling and monitoring platforms. Nine CVEs carry confirmed active exploitation, including SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, LiteLLM, and Starlette, and no patch availability was recorded for the day's set, so defenders should verify vendor advisories directly and apply compensating controls where fixes are not yet published.

  • Google Chrome carries three CVSS 9.6 vulnerabilities (CVE-2026-85042, CVE-2026-85047, CVE-2026-85050); update browsers across managed fleets
  • 52 critical CVEs (CVSS 9.0+), a 160% increase from the prior day's 20
  • 78 high-priority CVEs (CVSS 7.0-8.9), a 30% increase from the prior day's 60
  • Remote code execution dominates: themoos core-moos (three CVSS 9.8 flaws), Divi Ajax Filter and WPFunnels Mail Mint WordPress plugins, Dianping CAT, and MISP
  • 0% patch availability recorded across the 130 disclosed CVEs; confirm fix status directly with Google, Divi Engine, WPFunnels, MISP, and themoos
  • 9 CVEs show active exploitation, spanning SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, BerriAI LiteLLM, Sangoma Switchvox, and Starlette

Immediate action: Prioritize Google Chrome updates, exposed SonicWall SMA1000 and PaperCut MF/NG appliances, JFrog Artifactory, and internet-facing WordPress sites running Divi Ajax Filter or Mail Mint, along with Python services built on Starlette or LiteLLM. Patch availability was not recorded for these disclosures, so check vendor advisories for current fix status and restrict network exposure of affected systems until updates are confirmed.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation