Executive assessment
Today's brief leads with SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
What changed: CVE coverage: CVE-2026-83549, CVE-2026-83548. SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
Technical evidence: CVE-2026-83548; CVSS v3.1 10; weakness CWE-918, CWE-441; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: SonicWall states there is no workaround; organisations unable to patch immediately should contact SonicWall Technical Support to review appliances for indicators of compromise, and if indicators are found, re-image or redeploy the appliance, change all user and administrator passwords, and reset TOTP tokens. Both vulnerabilities are actively exploited in the wild, with no public proof-of-concept identified as of 2 September 2026. ([psirt.global.sonicwall.com](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016), [rapid7.com](https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild))
Action: Map CVE-2026-83548 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-83548)
Finding 02 — Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
What changed: Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2021-31886; CVSS v3.1 9.8; weakness CWE-170; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable or block FTP on TCP/21, isolate vulnerable controllers from untrusted networks, restrict external communication paths, and monitor for anomalous protocol use, repeated crashes and unexpected outbound traffic. Forescout publicly documented working research PoCs against WAGO 750-852 and 750-831 V01.04.16 PLCs, but the retrieved sources report no exploitation in the wild. ([forescout.com](https://www.forescout.com/blog/can-ai-create-plc-attacks-yes-but-it%E2%80%99s-not-that-easy-yet/), [certvde.com](https://certvde.com/de/advisories/VDE-2021-050/))
Action: Map CVE-2021-31886 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html)
Finding 03 — Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
What changed: Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3).
Technical evidence: CVE-2026-9586; CVSS v4.0 9.3; weakness CWE-89; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: If patching is delayed, restrict network access to the Switchvox interfaces and the unauthenticated /pa endpoint; inspect /var/log/switchvox/db-quirks.log for SQL-injection payloads and investigate network requests involving 176.65.148.184. Exploitation is confirmed in the wild: Horizon3 observed valid attempts against multiple honeypots on 30 August 2026, including a reverse-shell payload. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/), [horizon3.ai](https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-9586))
Action: Map CVE-2026-9586 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-9586)
Finding 04 — Cisco IOS XR Software Security Hardening Release: September 2026
What changed: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
Technical evidence: CVE-2026-20274; CVSS v3.1 9.8; weakness CWE-664; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst assessment: Apply generic network-device compensating controls immediately by restricting management and control-plane access to trusted out-of-band subnets, enforcing strict control plane policing (CoPP) and infrastructure ACLs on exposed interfaces, and disabling unused administrative services. For core and edge routing operating systems, multi-vulnerability hardening bundles typically address control-plane parsing flaws or management interface weaknesses that risk device instability, denial of service, or unauthorised control from reachable segments. Monitor route processors for abnormal process crashes or restarts, surges in CoPP drop counters, unexpected configuration modifications, and unexplained routing adjacency flaps. (Generic reasoning about this weakness class, not vendor-specific guidance; no additional source found.)
Action: Map CVE-2026-20274 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Security%20Hardening%20Release:%20September%202026%26vs_k=1)
Finding 05 — USN-8713-1: BioSig vulnerabilities
What changed: Mark Bereza and Lilith Wyatt discovered that BioSig incorrectly handled certain crafted input files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
Technical evidence: CVE-2026-22891; CVSS v3.1 9.8; weakness CWE-122; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching, block untrusted Intan CLP and Nicolet WFT files from reaching libbiosig-dependent applications, and monitor those applications for crashes, unexpected child processes or network connections. Public PoCs exist for both CVEs, while CISA’s CVE records classify observed exploitation as ‘none’. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22891/), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-20777/), [talosintelligence.com](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2361), +6 more)
Action: Map CVE-2026-22891 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8713-1)
Finding 06 — Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
What changed: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF).
Technical evidence: CVE-2026-20212; CVSS v3.1 9.8; weakness CWE-1327; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Until patching, use infrastructure ACLs to allow only required management and control-plane traffic to affected devices or deny TCP traffic to locally configured IP addresses on ports 43210 and 43211; supported NX-OS 10.6(3) devices can also use Live Protect shield lp00031 and monitor its hit log or %APPMGR-2-NXSECURE_CRIT_THREAT syslog events. Cisco PSIRT reports no known public announcements or malicious use. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr), [cisco.com](https://www.cisco.com/content/en/us/td/docs/dcn/nx-os/nexus9000/106x/release-notes/release-notes-nxos-live-protect-shield-1063.html), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-20212))
Action: Map CVE-2026-20212 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%209000%20Series%20Switches%20Silicon%20One%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1)
Finding 07 — Multiple vulnerabilities in Orval
What changed: CVE coverage: CVE-2026-72716, CVE-2026-71866. The cited advisories disclose: Import-time RCE via query-parameter default -> zod module-level template literal; Import-time RCE via schema property name -> computed-property-key injection in the zod client.
Technical evidence: CVE-2026-72716; CVSS v4.0 9.3; weakness CWE-1336; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-72716 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-p4cg-3328-rvfg)
Finding 08 — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control.
What changed: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control. CVE coverage: CVE-2026-72920.
Technical evidence: CVE-2026-72920; CVSS v3.1 9.8; weakness CWE-306; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not immediately possible, restrict the filer gRPC port to trusted administrative hosts, alert on SeaweedIdentityAccessManagement RPCs from non-administrative sources, and audit for unexpected users, access keys and elevated or wildcard policies. No public PoC was reported by TheHackerWire, and CVE-2026-72920 is absent from CISA's KEV catalogue version 2026.09.02. SeaweedFS versions before 4.24 are affected; version 4.24 contains the fix. ([github.com](https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-2v6v-25fm-p4fg), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-72920/), [thehackerwire.com](https://www.thehackerwire.com/seaweedfs-filer-unauthenticated-iam-access-cve-2026-72920/), +1 more)
Action: Map CVE-2026-72920 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-2v6v-25fm-p4fg)
Finding 09 — USN-8710-1: libevent vulnerabilities
What changed: Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or arbitrary code execution.
Technical evidence: CVE-2026-63382; CVSS v4.0 9.2; weakness CWE-444; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-63382 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8710-1)
Finding 10 — Kestra OSS OS Command Injection Vulnerability — Kestra OSS
What changed: CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability — Kestra OSS The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-49869.
Technical evidence: CVE-2026-49869; CVSS v3.1 10; weakness CWE-78, CWE-184, CWE-287, CWE-918; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Action: Map CVE-2026-49869 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-49869)
Finding 11 — Multiple vulnerabilities in Omnigent
What changed: CVE coverage: CVE-2026-62677, CVE-2026-62674, CVE-2026-62675. The cited advisories disclose: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE; Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE; Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools.
Technical evidence: CVE-2026-62674; CVSS v3.1 9; weakness CWE-94; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-62674 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-p8rw-8qj3-hf33)
Finding 12 — Multiple vulnerabilities in OpenChoreo
What changed: CVE coverage: CVE-2026-73667, CVE-2026-73840, CVE-2026-73841, CVE-2026-73843. The cited advisories disclose: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods; Cross-project command execution and wirelog view access via openchoreo-api exec and wirelogs endpoints; Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs.
Technical evidence: CVE-2026-73843; CVSS v3.1 9.6; weakness CWE-306, CWE-668, CWE-862; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-73843 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-2mw5-23gm-pccq)
Finding 13 — Socket.IO: Engine.IO WebTransport SID DoS
What changed: Socket.IO: Engine.IO WebTransport SID DoS The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-59724.
Technical evidence: CVE-2026-59724; CVSS v3.1 7.5; weakness CWE-20; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is delayed, disable WebTransport by removing 'webtransport' from the enabled transports, or block WebTransport endpoints at the reverse-proxy or HTTP/3 layer. OpenCVE records no exploitation and no CISA KEV listing, while the public fix commit contains a regression test using the 'proto' session ID. Engine.IO versions >=6.5.0 and <6.6.7 are affected when WebTransport is enabled; version 6.6.7 fixes the issue. ([github.com](https://github.com/advisories/GHSA-gr94-w7qr-f4j3), [opencve.alliance.unm.edu](https://opencve.alliance.unm.edu/cve/CVE-2026-59724), [github.com](https://github.com/socketio/socket.io/commit/1fa1f46cd420ac5b57bb4c04c959b58f3c79158c))
Action: Map CVE-2026-59724 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-gr94-w7qr-f4j3)
Finding 14 — Multiple vulnerabilities in Kirby
What changed: CVE coverage: CVE-2026-75594, CVE-2026-71415, CVE-2026-75592. The cited advisories disclose: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling; File upload permissions are not checked during processing of chunk data; Access to image files outside of the site root via path traversal in the media handling.
Technical evidence: CVE-2026-75594; CVSS v4.0 8.2; weakness CWE-22; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-75594 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-9vx2-j98c-p72w)
Finding 15 — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE).
What changed: elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE). CVE coverage: CVE-2026-81891.
Technical evidence: CVE-2026-81891; CVSS v3.1 8.1; weakness CWE-434; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-81891 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](https://github.com/advisories/GHSA-gxmj-r5rf-ggwq)