These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
CVE-2026-59822 lets an unauthenticated attacker open an authenticated session on LiteLLM’s MCP Streamable HTTP endpoint using nothing but a made-up Bearer token, thanks to an OAuth2 passthrough fallback that silently replaced failed key validation with an empty, but accepted, auth object. CISA added it to its Known Exploited Vulnerabilities catalog on September 2, separate from the supply chain compromise the same gateway suffered earlier this year.
CVE-2026-48710, nicknamed BadHost, lets an unauthenticated attacker bypass path-based security middleware in Starlette, the Python framework underneath FastAPI, vLLM, LiteLLM and countless MCP servers, by sending a single malformed character in the HTTP Host header. Belgium’s Centre for Cybersecurity issued a patch-immediately advisory, and CISA added it to its Known Exploited Vulnerabilities catalog on September 2.
CNIL fined Hopital Prive de la Loire 500,000 euros after an attacker used compromised credentials, with no multi-factor authentication in the way, to browse the medical records of 524,867 patients undetected through summer 2025. The regulator also found the hospital never notified 202,246 affected third parties, a separate violation of GDPR’s breach notification duty.
During routine network maintenance on September 1, a procedural error at Google caused an engineer to sequentially disconnect every fiber path across the routing devices in a us-central1-b cluster within about thirteen minutes, pushing traffic-drop rates to 100 percent at peak and leaving VMs unreachable from outside the zone for over four hours. The redundancy Google’s design assumed did not help, because the failure removed every redundant path at once.
SonicWall disclosed two SMA1000 vulnerabilities on September 1: a perfect-10 pre-auth SSRF in the Work Place portal (CVE-2026-83548) and a high-severity command injection in the Appliance Management Console (CVE-2026-83549). Chained together they give an unauthenticated attacker remote code execution on the appliance, and CISA added both to its KEV catalog with a federal remediation deadline of September 5.
CISA added Kestra OSS’s CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on September 2, giving US federal agencies until September 5 to patch a CVSS 10.0 flaw that lets an unauthenticated attacker run arbitrary code as root inside the workflow engine. The bug is a one-line authentication mistake, and any organisation running Kestra to orchestrate CI/CD or data pipelines needs to treat the same deadline as urgent, regardless of who set it.
An unauthenticated SQL injection flaw in Sangoma Switchvox, CVE-2026-9586, is being actively exploited to deploy reverse shells and cryptomining malware on internet-exposed VoIP servers. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, and a patch has existed since July 14, meaning every unpatched instance still online has had close to two months to be found.
Proxmox published advisory PSA-2026-00043-1 on September 1, warning that CVE-2023-54391, a critical authentication bypass in Proxmox VE 7.x, is being actively exploited with public proof-of-concept code. The catch: the fix only ever shipped in 8.0.4, and Proxmox VE 7.x has been end of life since July 2024, so any instance still on that branch has no patch to install, only an upgrade.
Elementor patched CVE-2026-32475 on August 19, a critical unauthenticated file upload flaw in Elementor Pro’s File Upload form field that lets an attacker plant and run PHP code on any of the roughly 6 million sites running the plugin. Wordfence has already blocked over 190,000 exploitation attempts, and any site still on 4.2.1 or earlier with a published form using that field is exposed.
VulnCheck watched attackers chain reconnaissance, credential probing and command-and-control setup against Langflow (CVE-2026-0768, root RCE) and Ruby on Rails (CVE-2026-66066, the KindaRails2Shell file-read-to-RCE flaw) over the same weekend, hitting UK honeypots dozens of times as they hunted for AWS keys, OpenAI keys and Rails secrets.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.