Sunday, September 6, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures centered on Google Chrome, Mikrotik RouterOS, and a cluster of WordPress plugins, alongside continued exploitation of SonicWall SMA1000 and PaperCut MF/NG. Critical CVEs rose to 33, a 14% increase from the prior day, while high-priority CVEs fell 19% to 54. Notable critical entries include CVE-2026-84352 and CVE-2026-84325 in Google Chrome, CVE-2026-86060 and CVE-2026-67276 in Mikrotik RouterOS, and CVE-2026-10196 in the Mail Mint WordPress plugin. Attack patterns skew toward remote code execution and authentication weaknesses in edge appliances, print management servers, and AI tooling such as HKUDS AutoAgent and BerriAI LiteLLM, with 10 vulnerabilities carrying confirmed active exploitation. Defenders should prioritize internet-facing SonicWall, Mikrotik, and PaperCut systems, restrict management interfaces to trusted networks, and confirm fix status against each vendor's advisory before assuming coverage.

  • Google Chrome carries three critical CVEs, including CVE-2026-85046 with confirmed active exploitation
  • 33 critical CVEs, up 14% from the prior day
  • 54 high-priority CVEs, down 19% from the prior day
  • Remote code execution and authentication weaknesses affect Mikrotik RouterOS, SonicWall SMA1000, PaperCut MF/NG, and WordPress plugins (Mail Mint, MemberDash, Frontend Admin)
  • Check internet-facing SonicWall SMA1000, Mikrotik RouterOS, PaperCut MF/NG, JFrog Artifactory, and Kestra deployments first
  • 10 CVEs have confirmed active exploitation, spanning edge appliances, print management, and AI tooling

Immediate action: Prioritize SonicWall SMA1000, PaperCut MF/NG, Mikrotik RouterOS, and Google Chrome, where active exploitation or critical scores affect widely deployed, internet-facing systems, and update JFrog Artifactory, Kestra, LiteLLM, and Starlette instances where exposed. Confirm fix status and affected versions in each vendor's advisory, and restrict management access to trusted networks until patches are applied.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation