cbcvebase.
← Exploited This Week

Exploited This Week — Aug 31–Sep 07, 2026

10 KEV · 32 newly weaponized · 3 EPSS surges

Patch now — added to CISA KEV

CVE-2026-48710
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-16) · CVSS 6.5 MEDIUM · EPSS 0.36 (98th pct)

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while…

Nuclei templateblogs_hackernews, blogs_microsoft, blogs_wiz, vuldb +1
CVE-2026-9586
Sangoma Switchvox SQL Injection Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-05) · CVSS 9.8 CRITICAL · EPSS 0.12 (96th pct)

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries…

blogs_hackernews, vuldb, vulncheck
CVE-2026-82329
JFrog Artifactory Improper Authentication Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-05) · CVSS 9.8 CRITICAL · EPSS 0.08 (94th pct)

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

blogs_hackernews, vuldb, vulncheck
CVE-2026-49869
Kestra OSS OS Command Injection Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-05) · CVSS 10 CRITICAL · EPSS 0.02 (79th pct)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth.…

blogs_hackernews, blogs_microsoft, vuldb, vulncheck
CVE-2026-82078
PaperCut NG/MF Unsafe Reflection Vulnerability
CISA KEV (added 2026-08-31, due 2026-09-14) · CVSS 9.1 CRITICAL · EPSS 0.02 (76th pct)

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against…

Metasploit moduleelastic_rules ruleblogs_checkpoint, blogs_hackernews, blogs_huntress, blogs_rapid7 +1
CVE-2026-83549
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-05) · CVSS 7.8 HIGH · EPSS 0.02 (75th pct)

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could…

blogs_hackernews, blogs_rapid7, vuldb, vulncheck
CVE-2026-81578
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-08-31, due 2026-09-14) · CVSS 9.8 CRITICAL · EPSS 0.02 (74th pct)

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions…

Metasploit moduleelastic_rules ruleblogs_checkpoint, blogs_hackernews, blogs_huntress, blogs_rapid7 +1
CVE-2026-85046
Google Chromium V8 Type Confusion Vulnerability
CISA KEV (added 2026-09-04, due 2026-09-18) · CVSS 8.8 HIGH · EPSS 0.01 (65th pct)

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

blogs_hackernews, vuldb, vulncheck
CVE-2026-59822
BerriAI LiteLLM Improper Authentication Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-16) · CVSS 8.2 HIGH · EPSS 0.01 (56th pct)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an…

blogs_hackernews, blogs_wiz, vuldb, vulncheck
CVE-2026-83548
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CISA KEV (added 2026-09-02, due 2026-09-05) · CVSS 10 CRITICAL · EPSS 0.01 (51th pct)

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized…

blogs_hackernews, blogs_rapid7, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-48558
SimpleHelp Authentication Bypass Vulnerability
CISA KEV (added 2026-06-29, due 2026-07-02) · CVSS 10 CRITICAL · EPSS 0.30 (98th pct)

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted…

Metasploit moduleblogs_bleepingcomputer, blogs_hackernews, blogs_talos, vuldb +1
CVE-2025-60689
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys…
CVSS 5.4 MEDIUM · EPSS 0.17 (97th pct)

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters…

ExploitDB PoC
CVE-2026-15013
miniOrange 5.4.3 - Unauthenticated Auth Bypass
CVSS 9.8 CRITICAL · EPSS 0.02 (73th pct)

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because…

ExploitDB PoCvuldb
CVE-2026-25544
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
CVSS 9.8 CRITICAL · EPSS 0.01 (53th pct)

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An…

ExploitDB PoCblogs_wiz
CVE-2026-59827
Metabase 0.61.0 - Authenticated Remote Code Execution
CVSS 8.8 HIGH · EPSS 0.03 (87th pct)

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize…

ExploitDB PoCvuldb
CVE-2026-67206
Wolf CMS 0.8.3.1 - RCE v
CVSS 8.8 HIGH · EPSS 0.01 (71th pct)

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and…

ExploitDB PoCvuldb
CVE-2026-41456
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that…
CVSS 5.1 MEDIUM · EPSS 0.01 (67th pct)

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can…

ExploitDB PoCvuldb
CVE-2026-65008
Grav CMS 2.0.7 - RCE
CVSS 9.8 CRITICAL · EPSS 0.02 (80th pct)

Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to…

ExploitDB PoC
CVE-2025-50455
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis…
CVSS 9.1 CRITICAL · EPSS 0.01 (59th pct)

SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the…

ExploitDB PoC
CVE-2025-51683
A blind SQL Injection (SQLi) vulnerability in mJobtime v15
CVSS 9.8 CRITICAL · EPSS 0.02 (77th pct)

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

blogs_huntress, vulncheck

+21 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2025-34300
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio
CVSS 10 CRITICAL · EPSS 0.78 (100th pct) · ↑ EPSS 0.51→0.78 (+0.27) over 7d

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary…

Metasploit moduleNuclei templateblogs_greynoiseio, vulncheck
CVE-2026-9198
IBM Langflow Code Injection Vulnerability
CISA KEV (added 2026-08-04, due 2026-08-07) · CVSS 9.8 CRITICAL · EPSS 0.57 (99th pct) · ↑ EPSS 0.35→0.57 (+0.22) over 7d

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default…

ExploitDB PoCMetasploit moduleNuclei templateblogs_hackernews, blogs_rapid7, vuldb, vulncheck
CVE-2026-23744
mcpjam inspector Missing Authentication for Critical Function
CVSS 9.8 CRITICAL · EPSS 0.66 (99th pct) · ↑ EPSS 0.45→0.66 (+0.21) over 7d

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the…

ExploitDB PoCMetasploit moduleNuclei templateblogs_greynoiseio, blogs_wiz, vulncheck

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.