securityonline.info 7 Sept 2026, 01:51 UTC

CISA KEV Missed Four Actively Exploited AI and WordPress Flaws

CISA KEV Missed Four Actively Exploited AI and WordPress Flaws
CyberSIXT Evidence Panel Source marked as original reporting

DAILY Cybersecurity’s weekly briefing contrasts active exploitation with the official CISA KEV catalog for the period 31 August to 6 September 2026. The CVE WATCHTOWER tracker logged 2,316 new disclosures in that week, including 271 rated critical and 708 high severity. Nine flaws were marked as ACTIVE by Daily Cybersecurity, with five of those later added to CISA KEV. Notably, four critical vulnerabilities surfaced only on Daily Cybersecurity’s feed, meaning organisations relying on KEV alone would have missed them.

Among the exploited items, several familiar names appear: CVE-2026-82329 (JFrog Artifactory), CVE-2026-9586 (Sangoma Switchvox SMB), CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA1000 – Work Place and AMC), and CVE-2026-85046 (Google Chrome V8). Daily Cybersecurity also flagged CVEs not yet listed in KEV, including CVE-2026-0768 (Langflow), CVE-2026-35029 (LiteLLM AI Gateway), CVE-2026-32475 (Elementor Pro), and CVE-2026-14894 (Super Forms).

The report highlights that four DC-exclusive flaws relate to AI tools and WordPress plugins, which saw substantial attention in detection tools and real-world attempts to misuse uploads.

SonicWall gateways are singled out as under active attack, with CVE-2026-83548 rated 10.0 (pre-auth SSRF) and CVE-2026-83549 (command injection) enabling unauthenticated code execution. Other notable items include CVE-2026-82078 and CVE-2026-81578 in PaperCut NG/MF, and several WordPress plugin flaws that facilitate unauthenticated web shell uploads.

Defenders are advised to prioritise internet-facing SonicWall, JFrog, and Switchvox systems, then patch affected WordPress sites and Chrome’s V8 bug, followed by Langflow, LiteLLM, Kestra, PaperCut, and Starlette instances.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline