Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers are actively exploiting critical Gitea RCE CVE-2026-60004 via the diffpatch endpoint, prompting CISA KEV addition and at least one cryptomining compromise.
CISA added CVE-2026-60004, a critical code injection flaw in Gitea's diffpatch endpoint, to its Known Exploited Vulnerabilities catalog after in-the-wild attacks. An attacker with repository write access, or an unauthenticated visitor on instances with open registration, can execute arbitrary shell commands as the Gitea OS user. A disclosed incident saw an automated scanner register an account and deploy a loader and cryptominer inside a Docker container within about 11 seconds, with no persistence mechanism found. Gitea patched the flaw in v1.27.1, and CISA ordered US federal civilian agencies to update by August 28, 2026.
Attackers exploit zero-days in consistently besieged SonicWall product
Two actively exploited SonicWall SMA 1000 zero-days chain to unauthenticated RCE; patches released and CISA added both to KEV.
SonicWall disclosed and patched two zero-days in SMA 1000 appliances: CVE-2026-83548, a maximum-severity pre-authentication SSRF, and CVE-2026-83549, a high-severity OS command injection. Rapid7 said chaining the flaws yields unauthenticated remote code execution, and CISA added both to its KEV catalog Wednesday. The vendor provided no IOCs or victim counts, urging customers to hunt for compromise, reimage or redeploy appliances, and reset all passwords and tokens. The product has faced repeated exploitation, including ransomware-linked flaws used by INC and Akira.
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
Critical unauthenticated RCE zero-day CVE-2026-75650 (StyleSmuggler) in Adobe Commerce and Magento is actively exploited; Adobe shipped hotfix VULN-39341 on September 7.
CVE-2026-75650 is a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, and Magento Open Source 2.4.6-2.4.9, exploited via malicious style properties that inject PHP code executed through a transactional email template. Active exploitation began September 4, 2026, three days before Adobe released Hotfix VULN-39341 (APSB26-146) on September 7, with multiple victim stores confirmed by Sansec and Disrex across at least two distinct campaigns. Attackers deploy a persistent implant at ~/.local/share/.gvfsd/gvfsd-user masquerading as kworker, fc-cache, or chronyd, sustained by a cron job, while a second operator dropped a PHP web shell in product image caches. Tenable classified it as a Vulnerability of Interest; it is not yet in CISA KEV as of September 8, and Adobe also recommends rotating encryption keys and all protected credentials.
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
2026-004: Critical Vulnerability in SharePoint Exploited
CVE-2026-20963 (CVSS 9.8), an unauthenticated RCE in on-prem SharePoint, was added to CISA's KEV on 18 March 2026 and is actively exploited.
CERT-EU warns about CVE-2026-20963, a CVSS 9.8 unauthenticated remote code execution flaw in SharePoint caused by deserialisation of untrusted data, affecting SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Microsoft raised the CVSS score on 17 March 2026 and the flaw entered CISA's Known Exploited Vulnerabilities catalogue on 18 March 2026. Three additional SharePoint RCE flaws (CVE-2026-26106, CVE-2026-26113, CVE-2026-26114) were fixed in the March 2026 release. CERT-EU urges immediate patching of internet-facing servers plus AMSI Full Mode, EDR deployment, ASP.NET machine key rotation, and compromise assessments.
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
SonicWall SMA1000 appliances face active exploitation of chained CVE-2026-83548 and CVE-2026-83549 enabling unauthenticated RCE; hotfixes released.
SonicWall disclosed on September 1, 2026 that CVE-2026-83548, a critical pre-authentication SSRF in the SMA1000 Appliance Work Place interface (CVSS 10.0), and CVE-2026-83549, an authenticated OS command injection in the Appliance Management Console, can be chained for unauthenticated remote code execution. Both vulnerabilities are confirmed exploited in the wild and were added to CISA's Known Exploited Vulnerabilities catalog. Affected SMA1000 models 6210, 7210 and 8200v on versions 12.4.3-03453 and 12.5.0-02835 platform-hotfix or earlier require upgrades to 12.4.3-03526 or 12.5.0-02952 platform-hotfixes.
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Research confirms in-the-wild exploitation of three JFrog Artifactory vulnerabilities, chained to gain administrative control, deploy Groovy plugins, and install Rust backdoors.
Wiz Research identified active exploitation of CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 in JFrog Artifactory between August 15 and September 8, 2026. Attackers chain the anonymous-token exposure (CVE-2026-42018) with the token scope-validation flaw (CVE-2026-42016) to obtain admin-scoped tokens, while CVE-2026-82329 allows unauthenticated administrative access in default configurations. Observed post-exploitation includes persistent administrator accounts created in under five minutes, malicious Groovy plugin deployment, ad-hoc command execution, Rust-based C2 backdoors dropped to writable paths, and webshell uploads. Wiz measured that 59-62% of organizations running Artifactory remained vulnerable to the chained CVEs weeks after disclosure, and the vulnerabilities were already included in CISA KEV.