VYPR
AI Brief2026-09-04· generated Sep 4, 2026

What you need to know today.

Actively Exploited SonicWall and JFrog Flaws Lead Today's Critical Vulnerability Briefing, Alongside Cisco and Sangoma Exploits.

SonicWall SMA1000 appliances are under active exploitation due to two zero-day vulnerabilities. CVE-2026-83548, a pre-authentication SSRF flaw, and another unpatched vulnerability allow unauthenticated remote attackers to achieve remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) has added these to its Known Exploited Vulnerabilities catalog, citing their use in attacks that deploy reverse shells and crypto miners. Organizations using SonicWall SMA1000 must apply available patches immediately to mitigate further compromise. The Register reported, and CyberScoop noted, that these flaws are being chained together.

JFrog Artifactory is facing exploitation of a critical authentication weakness, CVE-2026-82329, which allows unauthenticated attackers to gain administrative privileges under default configurations. This vulnerability has been observed in the wild, with attackers minting admin tokens shortly after its disclosure. CISA has added this to its KEV catalog, highlighting its immediate threat. Users are urged to review their Artifactory configurations and apply updates to prevent unauthorized administrative access and potential system compromise. The Hacker News reported on the rapid exploitation of this flaw.

Sangoma's Switchvox SMB Edition is targeted by CVE-2026-9586, a critical unauthenticated SQL injection vulnerability. Attackers are actively exploiting this flaw to gain unauthorized access and execute arbitrary code, as reported by Cyber Security News. The vulnerability resides in the /pa endpoint, where user-controlled input is directly concatenated into SQL queries. This allows attackers to bypass authentication and potentially take full control of the affected VoIP platform. CISA has also added this to its KEV catalog due to active exploitation.

Cisco is addressing multiple critical vulnerabilities across its product lines. CVE-2026-20212, a critical flaw in Cisco Nexus 9000 Series Switches, allows unauthenticated remote attackers to execute code with root privileges by exploiting exposed TCP ports. Additionally, Cisco IOS XR Software has several vulnerabilities, including CVE-2026-20274 and CVE-2026-20279, which have been addressed through software hardening releases. These issues underscore the importance of timely patching for network infrastructure. The Hacker News and SecurityWeek provided details on these Cisco vulnerabilities.

A wave of critical vulnerabilities has been disclosed affecting TOTOLINK T6 routers, specifically CVE-2026-51770, CVE-2026-51769, CVE-2026-51765, and CVE-2026-51705. These flaws, primarily related to incorrect access control within the router's MQTT and web interfaces, allow unauthenticated attackers to manipulate QoS settings, restart update checks, alter mesh network configurations, and rename mesh entries. These vulnerabilities could enable attackers to disrupt network operations or gain unauthorized control over the device's network functions. Vypr Intelligence reported on the extensive set of issues affecting this product.

ServiceNow has released patches for critical vulnerabilities in its AI platform, including CVE-2026-18886. This improper access control vulnerability could allow an unauthenticated user to create or modify instance data without proper authorization. While not yet on the KEV list, the critical nature of this flaw warrants immediate attention from ServiceNow customers to prevent data integrity issues and unauthorized modifications. GovInfoSecurity and SecurityWeek covered the patches.

WordPress sites are vulnerable to privilege escalation through two separate issues. CVE-2026-18550, affecting the Nokri Job Board theme, allows account takeover via insufficient reset token validation. Additionally, the MemberHero plugin, up to version 6.9, permits unauthenticated attackers to register new users with administrative roles due to a lack of restrictions on account field provisioning during registration. These flaws pose a significant risk to WordPress site administrators, potentially leading to complete site compromise.

Synthesized by Vypr AI
Actively Exploited SonicWall, JFrog, Cisco, and Sangoma Flaws Lead Briefing · VYPR