On 2 September 2026 CISA published a Rockwell Automation ICS advisory batch (ICSA-26-244-01 through ICSA-26-244-06) alongside Rockwell Trust Center advisories. ICSA-26-244-01 covers RSLinx Classic denial-of-service issues CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 and CVE-2026-9625 (critical/high per SecurityWeek's read of the vendor set; exploitation can crash the RSLinx Classic service until restart). ICSA-26-244-03 covers Logix Platform CVE-2026-9637 (improper restriction of operations within memory buffer) with vendor CVSS 3.x 7.5 on ControlLogix 5580 and CompactLogix 5380 version ranges listed in the CISA advisory; CISA states it is not aware of public exploitation. SecurityWeek also notes FactoryTalk Historian RCE, FactoryTalk Activation Manager privilege issues, ArmorStart XSS/DoS, and ControlFLASH arbitrary code execution among the same Tuesday drop. Apply Rockwell patches or workarounds from the Trust Center; segment OT management hosts.
Google's Stable Channel Update for Desktop (2 September 2026) promotes Chrome to 152.0.7977.75/.76 on Windows and Mac and 152.0.7977.75 on Linux with 26 security fixes. Critical: CVE-2026-84353 use-after-free in Shared Tab Groups and CVE-2026-84352 use-after-free in WebGL (both Google-reported). Nine High issues include FileSystem incorrect authorization (CVE-2026-84354), Skia information leak (CVE-2026-84359), Omnibox input validation (CVE-2026-84357), and several use-after-free / buffer issues in Proxy, Browser, Dawn, GPU and V8. Distinct from desk card cve-2026-79290 (earlier Chrome 152.0.7977.64/.65 Critical Aura/ANGLE set, 25 Aug). SecurityWeek says Mozilla shipped Firefox 155 the same day with patches for 29 defects including 13 high-severity use-after-free, sandbox escape, and memory-corruption issues. Update Chrome and Firefox promptly; this desk does not invent CVSS for Google's Critical labels.
Chrome Stable Channel Update for Desktop (2 Sep 2026)
BerriAI LiteLLM GHSA-7488-6r32-c95q (CVE-2026-59822) is High: the MCP Streamable HTTP auth path could let an unauthenticated attacker establish an MCP session with an arbitrary Bearer token when OAuth2 passthrough fallback replaced failed key validation with an empty UserAPIKeyAuth object, exposing configured MCP tools and connected services. Affected versions before 1.84.0; fixed in 1.84.0. GHSA publishes CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N; CISA KEV (2 Sep 2026) and The Hacker News cite 8.8. CISA added the CVE to KEV on evidence of active exploitation. Upgrade to 1.84.0+ or disable/block /mcp/ until patched.
Kestra GHSA-5vc5-wxxq-3fjx (CVE-2026-49869) is Critical: AuthenticationFilter whitelists any path whose last segment is configs via endsWith("/configs"), so unauthenticated callers can hit flow/execution APIs and, with default script plugins, achieve remote code execution as root in the worker container. GHSA CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10.0). Affected through 1.3.20; patched in 1.0.45 and 1.3.21. CISA added it to KEV on 2 September 2026. Upgrade Kestra OSS immediately; do not expose the webserver to untrusted networks until patched.
Kludex Starlette GHSA-86qp-5c8j-p5mr (CVE-2026-48710) is an HTTP request/response path confusion: affected builds rebuild request.url from an unvalidated Host header, so a malformed Host can make request.url.path differ from the path the router actually dispatched. Middleware that authorises on request.url.path can be bypassed. GHSA rates Moderate; CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). Affected through 1.0.0; patched in 1.0.1. CISA added it to the KEV catalog on 2 September 2026 based on evidence of active exploitation. Upgrade Starlette (and FastAPI stacks that pin it) to 1.0.1 or later; ensure front-end proxies reject malformed Host headers.
SonicWall's 2 September 2026 advisory SNWLID-2026-0016 (covered by SecurityWeek the same day) warns SMA1000 series secure remote access / SSL-VPN customers of two zero-days discovered and observed exploited internally. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, rated CVSS 10. CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC), rated CVSS 7.8, that an authenticated attacker can use for arbitrary OS commands and potential RCE. SonicWall says both have been exploited and the pair can be chained for unauthenticated remote code execution. Affected models: SMA1000 6210, 7210 and 8200v. Hotfixes 12.4.3-03526, 12.5.0-02952 and higher patch both issues. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. CISA added both CVEs to the KEV catalog on 2 September 2026.
SecurityWeek (2 September 2026) reports CVE-2026-84115 in Cleo Harmony file-transfer: improper privilege management in the JWT refresh token handler on /api/connections, where manipulating the Bearer argument can let a remote attacker elevate privileges. VulDB (listed as CNA-style record in public mirrors) says builds through 5.8.1.10 are affected, a public exploit exists, and upgrading to 5.8.1.11 fixes it. Cleo's Harmony 5.8.1 release notes list 5.8.1.11 as a 15 May 2026 limited/restricted build and do not expand on this CVE in the public notes SecurityWeek also noted thin vendor detail. WatchTowr (quoted by SecurityWeek) has reproduced the issue and flags Harmony as a frequent ransomware target historically. This desk does not invent a CVSS beyond what secondary reporting attributes; Cyber Security News cites 8.3 High for the same CVE. Patch to 5.8.1.11 or later; hunt anomalous /api/connections auth traffic.
Plex posted an official security notice on its forum on 1 September 2026 recommending that all Plex Media Server owners and Plex Desktop users update as soon as possible. Plex Media Server 1.43.3 and Plex Desktop 1.115.0 address a number of security issues. Plex says CVEs have been requested and that it will add details to the thread once they are published; this desk does not invent CVE identifiers or a CVSS. NAS package managers may lag; Plex says the updated package can be installed manually from its Downloads page. BleepingComputer (3 September 2026) reports Plex also emailed owners of affected versions urging immediate upgrade — unusual for the vendor — while still withholding vulnerability details. NEW 9 Sep: BleepingComputer citing Shadowserver says daily scans since 4 September 2026 still find over 36,000 internet-exposed Plex Media Server instances on vulnerable 1.43.2-and-earlier builds, with missing CVEs limiting automated detection. Automatic-update users should confirm they are on 1.43.3 or newer.
Manifold Security published GitSpawn research on 1 September 2026: several AI coding agents run git (status, diff and similar) to gather repo context at startup, in some products before a workspace-trust prompt or authentication. Those calls did not strip the repository's own git configuration. Git settings that name a helper program (including core.fsmonitor) then run as the developer, outside the agent sandbox, with no approval prompt. Manifold says clone, fetch or pull of a hostile URL does not carry this; the repository has to arrive as files with its .git directory already inside (zip, shared drive, USB). Named products and status at publication: Claude Code core.fsmonitor patched by 2.1.196 (confirmed on 2.1.193; reported 26 June, closed as duplicate); Claude Code ultrareview still unpatched on 2.1.252; Goose patched in 1.44.0 (CVE-2026-72718, maintainers 7.0); Hermes unpatched on 0.21.0 (CVE-2026-71963, VulnCheck CNA); Qwen Code unpatched on 0.22.3; Grok Build unpatched on 1.0.13; OpenAI Codex and Cursor patched (reports closed as duplicates). Manifold 1 September update says Codex and Cursor were also affected, reported, and have since been patched. Inspect .git/config before opening a received folder in an agent. This desk does not invent CVSS for the unpatched products.
GeoNetwork (OSGeo geospatial metadata catalog used behind many government and agency geoportals, including European INSPIRE backends) published advisories on 31 August 2026 for two flaws that chain to unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6 per The Hacker News citing the project) is a missing authorisation check on the formatter upload endpoint that lets an anonymous attacker write arbitrary .xsl or .zip formatter files. CVE-2026-58400 (CVSS 9.1 per the same reporting) is an unsafe Saxon XSLT configuration in the formatter engine that can call Runtime.exec / ProcessBuilder as the GeoNetwork process user once a malicious stylesheet is loaded. Fixes shipped earlier in 4.4.12 and 4.2.17 (8 July 2026); all 4.4.x through 4.4.11 and 4.2.x through 4.2.16 are affected. Vendor/project mitigations until patch: block write methods to /geonetwork/srv/api/formatters at the reverse proxy. Ethiack (Rafael Castilho) reported the chain and said it fingerprinted 121 internet-exposed affected instances across 39 countries, about 89% government/military/agency-related (exposure estimate, not confirmed compromises). The Hacker News (2 September) found no CISA KEV entry and no public in-wild exploitation reporting at disclosure. Primary advisories: GitHub GHSA-mh22-prqr-vf42 and GHSA-x898-729x-cc3r.
Cyber Security News (31 August 2026) reports CVE-2026-73296 in Microsoft's open-source UFO automation framework: Mobile Model Context Protocol servers (data collection on TCP 8020, action on TCP 8021) accepted MCP requests without authentication when bound for remote access (0.0.0.0). Default bind is localhost. An exposed action server can tap, swipe, type, launch apps and drive a connected Android device or emulator over ADB; the data server can return screenshots and UI hierarchy. CSN cites GitHub advisory GHSA-24fq-m9rr-g3mm (CWE-306 / CWE-862) and a CVSS of 9.4; that GitHub advisory URL returned 404 this pass, so the score is not confirmed from GitHub and is not copied into the CVSS field. Microsoft's fix is UFO 3.0.8, which adds mandatory bearer-token auth via UFO_MCP_API_KEY and is described as refusing startup if the key is missing. Until patched, keep Mobile MCP on localhost and block 8020/8021. Wire source until the GHSA page is readable.
JFrog's 28 August 2026 advisory rates CVE-2026-82329 Critical (CVSS 3.1 9.8): under default configuration, an unauthenticated attacker with network access may obtain administrative privileges on self-managed Artifactory. watchTowr told SecurityWeek (1 Sep) and BleepingComputer / The Hacker News (2 Sep) it has seen exploitation — attackers minting admin tokens, enumerating users/groups/federated topologies, and in limited cases creating backdoor users — from a small set of IPs without evidence of mass scanning yet. watchTowr describes a 'phantom' join key on instances without an additional join key configured, abused via JFrog Access to forge administrator credentials. Self-hosted patches: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20; JFrog says cloud was already fortified. Access tokens are independent credentials — upgrading the binary does not by itself revoke minted tokens, so rotate/revoke tokens and hunt anomalous admin activity after patching. CISA added CVE-2026-82329 to the KEV catalog on 2 September 2026. UPDATE 10–11 September 2026 (Wiz / THN): Wiz also saw CVE-2026-82329 abused in the wild alongside a separate 42018→42016 chain (15 Aug–8 Sep) that yields admin and drops Rust C2 / Groovy plugins — see desk cards cve-2026-42018 and cve-2026-42016. Distinct from cve-2026-66384.
JFrog security advisories (CVE-2026-82329, 28 Aug 2026)