Rosetta Daily · Sep 2, 2026
Three unrelated flaws share the same pattern today: SonicWall SMA 1000, Sangoma Switchvox, and JFrog Artifactory were all weaponized within days of a patch or disclosure, and none has reached the CISA KEV catalog yet — exploitation is outrunning the catalog's update cycle.
Actively Exploited (Not Yet in KEV)
SonicWall SMA 1000: Two Zero-Days Chained Together, Already Exploited in the Wild
SonicWall patched two zero-days in its SMA 1000 series secure mobile access appliances after in-the-wild exploitation. One is an unauthenticated SSRF in the appliance management interface (CVE-2026-83548, CVSS 10.0); the vendor says a second flaw completes an attack chain with it but has not disclosed its CVE number. Both were found by SonicWall's own researchers.
Sources: The Hacker News · Bleeping Computer
Sangoma Switchvox: Unauthenticated SQL Injection to RCE, Already Used to Deploy Reverse Shells
CVE-2026-9586 (CVSS 9.3) affects Switchvox SMB Edition 8.3 (104997). Attackers can remotely execute code as root via SQL injection with no credentials, and are already using it to plant reverse shells on victim appliances.
Sources: The Hacker News
JFrog Artifactory: New Auth Bypass Exploited Days After Disclosure to Mint Admin Tokens
CVE-2026-82329 (CVSS 9.8) is an authentication weakness that, under default configuration, grants administrative access. Attackers began exploiting it in the wild days after security firm watchTowr disclosed it — a different flaw in the same product from the path-traversal CVE (CVE-2026-66384) already in the KEV catalog.
Sources: The Hacker News
Critical Vulnerabilities
Rockwell Automation: CISA Issues Six ICS Advisories in One Day, Covering RSLinx Classic, Logix, ArmorStart LT and More (CVSS up to 9.2)
CISA published six ICS advisories on September 1: four denial-of-service flaws in RSLinx Classic (CVE-2026-9621/9622/9624/9625, CVSS 8.6-9.2), one in the Logix platform (ControlLogix/CompactLogix/GuardLogix, CVE-2026-9637), and one in ArmorStart LT (CVE-2026-19472, CVSS 8.7), all triggerable with crafted CIP packets; an out-of-bounds write in FactoryTalk Historian ME enabling remote code execution (CVE-2025-12768, CVE-2026-12661, CVSS 8); and a privilege-escalation flaw in the FactoryTalk Activation Manager installer (CVE-2026-16675, CVSS 8.5). Most require a device or service restart to recover.
Sources: CISA ICSA-26-244-01 · CISA ICSA-26-244-06
Firefox 155: Multiple Sandbox Escapes and Privilege Escalations (CVSS up to 9.6)
Mozilla fixed six high-severity flaws, including two use-after-free sandbox escapes in the DOM component (CVE-2026-84121, CVE-2026-84119, both CVSS 9.6) and privilege escalations in the Graphics/WebGPU and WebDriver BiDi components (CVSS 8.8 each). Firefox ESR and Thunderbird are affected too.
Sources: NVD CVE-2026-84121 · NVD CVE-2026-84119
Erlang/OTP inets httpd: 11 Flaws Spanning Denial of Service, Request Smuggling, and Protected-Directory File Reads (CVSS 8.2-8.7)
A single HTTP server module disclosed 11 CVEs at once: unenforced body-size and connection limits and chunked-encoding parsing bugs enable denial of service; co-present TE/CL headers and unhandled obs-fold continuation lines enable request smuggling; and case and double-slash path-normalization bugs let attackers read files inside mod_auth-protected directories. All are remotely triggerable without authentication.
Sources: NVD CVE-2026-74835 · NVD CVE-2026-73812
Dell PowerStore: Eight Flaws Enable Privilege Escalation to Root (CVSS 8.8 each)
An authenticated low-privilege user can chain code injection, OS command injection, and authentication-spoofing flaws (CVE-2026-79686, 58569, 79684, 58572, 58571, 79683, 58575, 76111) to escalate to administrator or root.
Sources: NVD CVE-2026-58569 · NVD CVE-2026-58571
Kyverno: Four Flaws Spanning Policy Bypass, SSRF, and Credential Theft (CVSS 8.3-9.4)
This Kubernetes admission controller mishandles overlapping policy exceptions (CVE-2026-84200, CVSS 9.4): the less restrictive exception wins, letting attackers bypass rules such as a hostPath-mount block. Its apiCall feature carries an SSRF (CVE-2026-84196) and automatically attaches the admission controller's own ServiceAccount token to outbound requests (CVE-2026-84195), letting an attacker exfiltrate that token and take over the whole cluster. NVD also re-listed a 2023 weak-cipher issue today (CVE-2023-54356, CVSS 9.3, 3DES cipher suites).
Sources: NVD CVE-2026-84200 · NVD CVE-2026-84196
Nearly 22,000 Exposed Microsoft Exchange Servers Remain Vulnerable to Mailbox Hijacking
Bleeping Computer reports nearly 22,000 internet-facing Exchange servers are still unpatched against a high-severity authentication-bypass flaw that lets attackers hijack every mailbox on the server; the report did not give a CVE number.
Sources: Bleeping Computer
AI Security
Unit 42 Documents a Real Intrusion Where an Autonomous AI Agent Breached an Enterprise Network in Hours
Palo Alto Networks' Unit 42 published a case study of an attacker who used autonomous AI agents to breach an enterprise network, completing in hours a chain of steps that traditionally required manual operator effort.
Sources: Unit 42
Researchers Use Claude to Port an Unauthenticated RCE Exploit From One PLC to Another
Forescout Research–Vedere Labs says it used Anthropic's Claude to port a working pre-authentication remote code execution exploit — targeting CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command — from one WAGO PLC model to a different one, executing attacker-supplied ARM shellcode on live hardware.
Sources: The Hacker News
MLflow: The statsmodelsFlavor Bypasses the Official Pickle-Deserialization Safety Switch, Enabling RCE via a Crafted Model File
MLflow ships MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False to block unsafe pickle deserialization, but the statsmodels model loader implements no such check at all. An attacker who places a crafted model artifact in any reachable model store can trigger arbitrary code execution the moment mlflow.pyfunc.load_model() loads it.
Sources: GitHub Security Advisories
Supply Chain and Web Security
BGP Hijack Delivers a Malicious Virtualizor Update, Compromising Some Hypervisor Hosts at Root Level
Attackers hijacked BGP routing to redirect Virtualizor VPS-management software's update traffic to a malicious server, pushing a backdoored package to some installations. One hosting provider said 5 of the 34 Virtualizor hosts it checked were compromised at the root level; the incident window began around August 28 at 20:57 UTC.
Sources: The Hacker News · Bleeping Computer
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seed Phrases
Composer theme packages inject JavaScript into Vietnamese movie- and comic-streaming sites, running mobile ad fraud and gambling redirects against visitors while deploying spyware against unpatched iOS devices to steal crypto wallet seed phrases.
Sources: The Hacker News
Other
Iran-Linked Nimbus Manticore Poses as Recruiters, Delivers Cross-Platform RATs Through Fake Coding Tests
Kaspersky attributes two previously undocumented malware families, built with Node.js and JavaScript, to the group, extending its targeting to Linux and macOS.
Sources: The Hacker News
Aesto Health Data Breach Affects 9.5 Million Patients
Healthcare company Aesto Health disclosed a data breach affecting more than 9.5 million people.
Sources: Bleeping Computer
FBI Investigates Dark-Web Sale of 153 Million Driver's License Scans
Krebs on Security reports a newly launched dark-web identity-theft service selling more than 153 million U.S. and Canadian driver's license scans, apparently sourced from a Louisiana-based identity-verification company; the FBI's New Orleans field office has opened a formal inquiry into the source.
Sources: Krebs on Security
Law Enforcement Coalition Dismantles Sality Botnet Infrastructure
Authorities from the U.S., Bulgaria, Hungary, and Romania, working with CrowdStrike and the Shadowserver Foundation, took down the long-running Sality peer-to-peer botnet's infrastructure on August 31, using the botnet's own P2P mechanics to cut off new malware payloads.
Sources: Bleeping Computer · The Hacker News