Posting Date: 2026/09/16
【Vulnerability Alert】CISA Added 10 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/31-2026/09/06)
- Subject:【Vulnerability Alert】CISA Added 10 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/31-2026/09/06)
- Description:
- Forwarded from TWCERTCC (Taiwan Computer Network Crisis Response and Coordination Center) Security Alert TWCERTCC-200-202609-00000009
- 【CVE-2026-82078】PaperCut NG/MF Unsafe Reflection Vulnerability (CVSS v3.1: 9.1)
- 【Exploited by Ransomware: Unknown】 PaperCut NG/MF has an unsafe reflection vulnerability that may allow an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode located on the application classpath under the security context of the PaperCut server process.
- 【CVE-2026-81578】PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 9.8)
- 【Exploited by Ransomware: Unknown】 PaperCut NG/MF has a missing authentication for critical function vulnerability that allows an unauthenticated remote attacker to modify specific system configurations.
- 【CVE-2026-59822】BerriAI LiteLLM Improper Authentication Vulnerability (CVSS v3.1: 8.2)
- 【Exploited by Ransomware: Unknown】 The MCP Streamable HTTP endpoint of BerriAI LiteLLM has an improper authentication vulnerability that may allow an unauthenticated attacker to use an arbitrary Bearer token to create an authenticated MCP session.
- 【CVE-2026-48710】Kludex Starlette HTTP Request/Response Smuggling Vulnerability (CVSS v3.1: 6.5)
- 【Exploited by Ransomware: Unknown】 Kludex Starlette has an HTTP request/response smuggling vulnerability that may allow an attacker to inject a path into the Host field and place it before the actual path; when the system's authentication mechanism relies on the reconstructed URL path, this may lead to issues such as authentication bypass.
- 【CVE-2026-49869】Kestra OSS OS Command Injection Vulnerability (CVSS v3.1: 10.0)
- 【Exploited by Ransomware: Unknown】 Kestra OSS has an OS command injection vulnerability that may allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
- 【CVE-2026-82329】JFrog Artifactory Improper Authentication Vulnerability (CVSS v3.1: 9.8)
- 【Exploited by Ransomware: Unknown】 JFrog Artifactory has an improper authentication vulnerability that, under default configurations, may allow an unauthenticated attacker with network access to gain administrative privileges.
- 【CVE-2026-9586】Sangoma Switchvox SQL Injection Vulnerability (CVSS v3.1: 9.8)
- 【Exploited by Ransomware: Unknown】 Sangoma Switchvox has a SQL injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database, including performing database operations and remote code execution, by sending a single crafted request.
- 【CVE-2026-83548】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
- 【Exploited by Ransomware: Unknown】 SonicWall SMA1000 Appliances has a server-side request forgery vulnerability that may allow an unauthenticated remote attacker to access sensitive functions without authorization and perform unauthorized operations.
- 【CVE-2026-83549】SonicWall SMA1000 Appliances OS Command Injection Vulnerability (CVSS v3.1: 7.8)
- 【Exploited by Ransomware: Unknown】 SonicWall SMA1000 Appliances has an OS command injection vulnerability that may allow an authenticated remote attacker with administrative privileges to execute arbitrary OS commands, potentially leading to remote code execution.
- 【CVE-2026-85046】Google Chromium V8 Type Confusion Vulnerability (CVSS v3.1: 8.8)
- 【Exploited by Ransomware: Unknown】 Google Chromium V8 has a type confusion vulnerability. A remote attacker can execute arbitrary code within the sandbox via a crafted HTML web page. This vulnerability may affect multiple web browsers built on Chromium, including but not limited to Google Chrome, Microsoft Edge, and Opera.
- Affected Platforms:
- 【CVE-2026-82078】Please refer to the officially listed affected versions https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- 【CVE-2026-81578】Please refer to the officially listed affected versions https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- 【CVE-2026-59822】Please refer to the officially listed affected versions https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q
- 【CVE-2026-48710】Please refer to the officially listed affected versions https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
- 【CVE-2026-49869】Please refer to the officially listed affected versions https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx
- 【CVE-2026-82329】Please refer to the officially listed affected versions https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- 【CVE-2026-9586】Please refer to the officially listed affected versions https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026
- 【CVE-2026-83548】Please refer to the officially listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- 【CVE-2026-83549】Please refer to the officially listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- 【CVE-2026-85046】Please refer to the officially listed affected versions https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
- Recommended Actions:
- 【CVE-2026-82078】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- 【CVE-2026-81578】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- 【CVE-2026-59822】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q
- 【CVE-2026-48710】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
- 【CVE-2026-49869】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx
- 【CVE-2026-82329】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- 【CVE-2026-9586】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026
- 【CVE-2026-83548】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- 【CVE-2026-83549】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
- 【CVE-2026-85046】 The vendor has released a fix for the vulnerability. Please update to the relevant version https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
- References:
Computer and Communication Center
Network System Division