Saturday, September 5, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Browser and mail client vulnerabilities in Google Chrome, Mozilla Firefox, and Thunderbird lead yesterday's disclosures, alongside a cluster of critical WordPress plugin flaws and two IBM enterprise products. The day produced 29 critical CVEs (down 44% from 52) and 67 high-priority CVEs (down 14% from 78), a marked drop in volume from the prior day. Notable critical issues include CVE-2026-84129 affecting Mozilla Firefox and Thunderbird (CVSS 9.8), CVE-2026-18658 in IBM Operational Decision Manager (CVSS 9.8), and CVE-2026-83627 in the wpmudev Hummingbird Performance WordPress plugin (CVSS 9.8). Confirmed active exploitation spans 10 CVEs, including SonicWall SMA1000 appliances, PaperCut MF/NG print management, JFrog Artifactory, and a Chrome flaw, indicating attacker focus on edge devices and developer infrastructure. No patches were confirmed at disclosure time, so defenders should verify vendor advisories directly and apply compensating controls where fixes are not yet available.

  • Mozilla Firefox and Thunderbird (CVE-2026-84129, CVE-2026-84637) and Google Chrome (CVE-2026-84354, CVE-2026-84324) carry critical CVSS 9.0+ flaws affecting end-user endpoints broadly
  • 29 critical CVEs disclosed, down 44% from 52 the prior day
  • 67 high-priority CVEs disclosed, down 14% from 78 the prior day
  • WordPress plugin exposure continues: Hummingbird Performance, ComboBlocks, MStore API, and AI Website Builder all rated CVSS 9.8; IBM Operational Decision Manager and Instana Agent also critical
  • Patch availability confirmed at 0% at disclosure; validate vendor advisories for Chrome, Firefox, Thunderbird, IBM, and affected WordPress plugins
  • 10 CVEs under active exploitation, including SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, LiteLLM, and Starlette

Immediate action: Prioritize updating Google Chrome, Mozilla Firefox, and Thunderbird across endpoints, and audit WordPress installations for Hummingbird Performance, ComboBlocks, MStore API, and AI Website Builder plugins. Internet-facing SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, and Kestra deployments are under active exploitation and should be isolated or patched first. No patches were confirmed at disclosure, so check vendor advisories directly and apply vendor mitigations or network restrictions until fixes are available.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation