Tuesday, September 8, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures were led by a CVSS 10 vulnerability in Adobe Commerce and a pair of critical flaws in Dell Secure Connect Gateway, alongside maximum-severity issues in D-Link and TOTOLINK routers. Critical CVEs rose to 35, a 75% increase over the prior day, while high-priority CVEs climbed to 81, up 45%. Notable entries include CVE-2026-75650 (Adobe Commerce, CVSS 10), CVE-2026-80238 and CVE-2026-61410 (Dell Secure Connect Gateway), CVE-2026-19593 (OpenAI Codex Desktop, CVSS 9.8), and CVE-2026-84133 (Mozilla Firefox and Thunderbird, CVSS 9.8). Enterprise e-commerce, remote support gateways, SAP NetWeaver, and developer tooling feature prominently, with 8 CVEs carrying confirmed active exploitation, including JFrog Artifactory, SonicWall SMA1000, LiteLLM, Starlette, and Google Chrome. Defenders should prioritize internet-facing Adobe Commerce storefronts and Dell and SonicWall gateway appliances, restrict management interfaces on affected routers, and confirm fix status for each product in the vendor advisory.

  • Adobe Commerce CVE-2026-75650 (CVSS 10) and D-Link DIR-822A CVE-2026-86296 (CVSS 10) top the day's disclosures
  • 35 critical CVEs disclosed, up 75% from the prior day's 20
  • 81 high-priority CVEs disclosed, up 45% from the prior day's 56
  • Dell Secure Connect Gateway carries two critical flaws (CVE-2026-80238, CVE-2026-61410), joined by critical issues in SAP NetWeaver, LibreNMS, OpenAI Codex Desktop, and Mozilla Firefox and Thunderbird
  • Check Adobe Commerce, Dell Secure Connect Gateway, SonicWall SMA1000, JFrog Artifactory, and Chrome deployments first
  • 8 CVEs show confirmed active exploitation, including Kestra, Sangoma Switchvox, LiteLLM, and Starlette

Immediate action: Prioritize patching Adobe Commerce, Dell Secure Connect Gateway, SonicWall SMA1000, JFrog Artifactory, and Google Chrome, and isolate or restrict management access to affected D-Link and TOTOLINK routers. Confirm fix status and affected versions for each product in the vendor's advisory before scheduling remediation.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation