Back to Archive
THREAT INTELLIGENCE BRIEFยทFriday, September 4, 2026ยทAI-Powered

This threat briefing highlights immediate risks from multiple actively exploited vulnerabilities.

This threat briefing highlights immediate risks from multiple actively exploited vulnerabilities. The top priority is an unauthenticated SQL injection flaw in Sangoma Switchvox (CVE-2026-9586), which is listed on the CISA KEV catalog and requires immediate patching. Additionally, Google has released an emergency patch for a Chrome zero-day (CVE-2026-85046) confirmed to be exploited in the wild, affecting a massive user base. We are also tracking active exploitation of a critical authentication bypass in Citrix NetScaler (CVE-2026-19490) and mass exploitation attempts against WordPress plugins (CVE-2026-14894), demanding urgent attention.

52 articles analysed6 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities5

Article Analyses (5)

Sangoma Switchvox Vulnerabilities Exploited in the Wild

high
CVE-2026-9586
KEVEPSS 11.8%

Details

An unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, is being actively exploited in Sangoma Switchvox systems. The flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution on the target system.

Affected Systems

Sangoma Switchvox

Potential Impact

Complete takeover of the affected Switchvox private branch exchange (PBX) system, leading to unauthorized access, data exfiltration, service disruption, and potential lateral movement into the broader corporate network.

Mitigations

Immediately apply patches provided by Sangoma. As this vulnerability is listed on the CISA KEV catalog, it is a known exploited threat. All organizations using Sangoma Switchvox are strongly advised to patch immediately.

SecurityWeekDraft Post

[CRITICAL] "Google patches actively exploited Chrome zero-day (CVE-2026-85046)"

critical
CVE-2026-85046
EPSS 0.5%

Details

A high-severity type confusion vulnerability (CVE-2026-85046) in the V8 JavaScript engine is being actively exploited in the wild. Google has confirmed the existence of an exploit. This flaw allows a remote attacker to execute arbitrary code by convincing a user to visit a malicious website.

Affected Systems

Google Chrome versions prior to 152.0.7977.82/.83 for Windows/macOS and 152.0.7977.82 for Linux.

Potential Impact

Successful exploitation could lead to arbitrary code execution on end-user workstations, enabling attackers to install malware, steal sensitive data (credentials, financial information), or gain an initial foothold in the network.

Mitigations

Ensure all Chrome instances are updated to the latest version immediately. The update is rolling out automatically, but manual verification and forced updates are recommended for all corporate assets.

Help Net SecurityDraft Post

[CRITICAL] "Critical Citrix NetScaler auth bypass now leveraged in attacks"

critical
CVE-2026-19490
EPSS 3.4%

Details

Attackers are actively exploiting a critical-severity authentication bypass vulnerability (CVE-2026-19490) in Citrix NetScaler. The flaw allows an attacker to bypass authentication and gain unauthorized access.

Affected Systems

Citrix NetScaler (specific versions to be confirmed from vendor advisory).

Potential Impact

Exploitation can lead to unauthorized access to sensitive corporate resources, session hijacking, and compromise of the network perimeter, creating a significant risk of data breach and further intrusion.

Mitigations

Apply the security patches released by Citrix immediately. Monitor for any signs of compromise, such as unusual login patterns or system behavior on NetScaler appliances.

BleepingComputerDraft Post

[CRITICAL] "Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws"

critical
CVE-2026-14894
EPSS 5.3%

Details

A critical vulnerability in the WordPress plugin 'Super Forms โ€“ Drag & Drop Form Builder' (CVE-2026-14894, CVSS 9.8) is being targeted in widespread exploit attempts. The flaw allows unauthenticated attackers to upload arbitrary files, including web shells, leading to remote code execution (RCE).

Affected Systems

WordPress sites using the 'Super Forms โ€“ Drag & Drop Form Builder' plugin (check vendor for patched versions).

Potential Impact

Successful exploitation results in a full compromise of the web server, enabling attackers to deface the website, steal customer data, host malicious content, or use the server as a pivot point to attack the internal network.

Mitigations

Update the 'Super Forms' plugin to the latest patched version immediately. Review web server file systems for any suspicious or unknown files, particularly in upload directories.

The Hacker NewsDraft Post

[HIGH] "12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover"

high
CVE-2026-6471
EPSS 0.3%

Details

A 12-year-old vulnerability (CVE-2026-6471) in PostgreSQL's logical decoding feature allows an attacker with low-level replication privileges to execute arbitrary code as the database's operating system user. This can be escalated to gain permanent superuser privileges and backdoor the database.

Affected Systems

PostgreSQL versions before 18.6, 17.11, 16.15, 15.19, and 14.24.

Potential Impact

Complete compromise of the PostgreSQL database and underlying server, leading to catastrophic data loss, corruption, or theft of all stored information. The attacker could gain persistent access to critical infrastructure.

Mitigations

Update all PostgreSQL instances to the latest patched versions. Review accounts with the REPLICATION attribute and restrict them to only trusted users.

SecurityWeekDraft Post
Generated by gemini-2.5-pro