Compiled from 52 monitored sources · 222 articles reviewed
Today’s Briefing
SonicWall disclosed CVE-2026-83548 and CVE-2026-83549 in SMA1000 series appliances, both zero-days under active exploitation that can be chained for unauthenticated remote code execution. CISA added seven vulnerabilities to the KEV catalogue including CVE-2026-9586 in Sangoma Switchvox, CVE-2026-82329 in JFrog Artifactory allowing unauthenticated administrative access under default configuration, and CVE-2026-49869 in Kestra OSS permitting unauthenticated workflow creation and execution. Mozilla patched two critical sandbox escape vulnerabilities in Firefox and Thunderbird, CVE-2026-84121 and CVE-2026-84119, both use-after-free flaws in DOM components. VMware released fixes for critical flaws in Spring Framework and Spring Security, including CVE-2026-59283 affecting SpEL expression evaluation and CVE-2026-59270 in the embedded UnboundID LDAP server that unconditionally registers administrative credentials and binds to all network interfaces.
Top Stories
- CC-4840 - Exploitation of Zero-Day Vulnerabilities in SonicWall SMA1000 Series Appliances
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog
- Rockwell Automation Logix Platform
- Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
- Claude Mythos only model to complete full cyber kill chain, experts say
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.