Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
blog

FOCUS FRIDAY: TPRM Insights on Critical Vulnerabilities in PaperCut MF/NG, SonicWall SMA1000, Sangoma Switchvox, and MongoDB BI Connector

Published

Sep 4, 2026

Authors

Ferdi Gül

Contributors

Hakan Karabacak

Introduction

This week's Focus Friday® covers four FocusTags® spanning enterprise print management, secure remote access, business communications, and database connectivity infrastructure. PaperCut MF/NG, SonicWall SMA1000, and Sangoma Switchvox each carry confirmed active exploitation — including two zero-day exploit chains and a mass-scanning campaign that began within hours of a public proof-of-concept release. MongoDB BI Connector rounds out the week with two patched vulnerabilities affecting availability and credential security in database-connected analytics environments.

The most operationally urgent events this week are the PaperCut and SonicWall exploit chains. PaperCut's first emergency patch was proven bypassable by a public Metasploit module — making Emergency Patch Release 2 mandatory for all organizations that applied only the initial fix. SonicWall's two zero-days were added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026, and SonicWall has confirmed active exploitation of both flaws. Sangoma Switchvox's unauthenticated SQL injection flaw — also added to CISA's KEV catalog on September 2 — is being actively mass-exploited by automated tooling, and Horizon3 honeypot data confirms large-scale scanning is already underway. TPRM professionals should treat all three as requiring immediate vendor engagement and patch verification.

Filtered view of vendors with PaperCut MF/NG - Aug2026 FocusTag® on the Black Kite platform.

Filtered view of vendors with PaperCut MF/NG - Aug2026 FocusTag® on the Black Kite platform.

PaperCut MF/NG - Aug2026 (CVE-2026-81578, CVE-2026-82078)

What is this vulnerability?

PaperCut MF and PaperCut NG are enterprise print management platforms widely deployed across enterprises, universities, and government organizations to manage printers, copiers, and document workflows. Two critical zero-day vulnerabilities — CVE-2026-81578 and CVE-2026-82078 — have been confirmed as actively exploited in the wild and can be chained to achieve unauthenticated remote code execution against the PaperCut Application Server. CVE-2026-81578 is an authentication bypass exploiting Apache Tapestry's dual-page request format: PaperCut validates access to the displayed page but not the executed page, allowing an unauthenticated attacker to reach privileged administrative configuration components by naming a public error page as the display target. CVE-2026-82078 is an unsafe dynamic class loading flaw in PaperCut's database connection utilities that enables an attacker who has gained configuration write access to instantiate arbitrary Java classes and chain execution through a bundled JavaScript engine to spawn OS-level processes as the PaperCut server process.

PaperCut has confirmed customer incidents, and Rapid7's Stephen Fewer published a Metasploit module covering the full exploit chain across the 24.x, 25.x, and 26.x branches. Critically, the first emergency patch was subsequently proven bypassable by this public Metasploit module — making the mandatory second emergency patch (Release 2) the only complete remediation. PaperCut explicitly states that all versions of NG and MF are potentially affected; patches are available in versions 24.1.10, 25.0.13, and 26.0.5 via Emergency Patch Release 2. Observed post-exploitation tradecraft includes whoami, nltest /dclist:, and quser reconnaissance, followed by SimpleHelp remote access service installation and AnyDesk deployment for persistent access — indicating attackers are converting PaperCut access into durable network footholds.

Why should TPRM professionals care?

PaperCut's print management infrastructure is deeply embedded in enterprise networks, and its Application Server holds privileged access to printer configurations, user account databases, and internal network resources. PaperCut has a well-documented exploitation history — CVE-2023-27350 was weaponized by ransomware groups in 2023, establishing it as a high-value, repeatedly targeted platform. The public Metasploit module reduces weaponization of this new exploit chain to a single command, and the fact that the first emergency patch was proven bypassable means that any third-party organization that applied only the initial fix remains fully exposed. For TPRM teams, this requires explicit confirmation that vendors have installed Emergency Patch Release 2 specifically — not just any PaperCut patch. Post-exploitation deployment of SimpleHelp and AnyDesk as persistent remote access tools means that successful PaperCut exploitation may be followed by sustained attacker presence within vendor networks.

What questions should TPRM professionals ask vendors?

  1. Have you applied PaperCut Emergency Patch Release 2 — specifically versions 24.1.10, 25.0.13, or 26.0.5 — to all PaperCut MF and NG Application Servers and Site Servers?
  2. If only the first emergency patch was applied, what is your timeline for deploying Release 2, given that the original patch has been proven bypassable by a publicly available Metasploit module?
  3. Have you restricted the PaperCut web management interface to trusted internal IP addresses using firewall rules or reverse proxy controls, with no direct public internet exposure?
  4. Have you reviewed server logs for indicators of compromise including entries such as "jdbc:derby:memory:pwn;create=true", "VALUES CAST(X'cafebabe", and randomly-named .class files under the server/lib directory?
  5. If indicators of compromise are found, are you treating the affected PaperCut server as requiring a full rebuild from a clean pre-incident backup, rather than attempting in-place remediation?

Remediation recommendations

  • Install Emergency Patch Release 2 (versions 24.1.10, 25.0.13, or 26.0.5) on all PaperCut MF and NG Application Servers and Site Servers immediately; organizations that applied only the first emergency patch remain fully exposed and must re-patch.
  • Restrict PaperCut web interface access to trusted internal IP ranges using firewall rules or reverse proxy restrictions and remove all direct public internet exposure, even if suspicious activity has not yet been observed.
  • Review server.log for IoC strings including jdbc:derby:memory:pwn;create=true, VALUES CAST(X'cafebabe, and randomly-named .class, .cmd, and .out files under the server/lib and server/data/content directories.
  • Treat any confirmed compromised PaperCut server as requiring a complete rebuild from a clean pre-incident backup; patching alone is insufficient after active exploitation, and PaperCut explicitly recommends this approach.
Black Kite’s PaperCut MF/NG - Aug2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite’s PaperCut MF/NG - Aug2026 FocusTag® details critical insights on the event for TPRM professionals.

SonicWall SMA1000 - Aug2026 (CVE-2026-83548, CVE-2026-83549)

What is this vulnerability?

SonicWall SMA (Secure Mobile Access) 1000 series appliances are enterprise-grade SSL VPN gateways used by medium to large organizations, government agencies, and managed security service providers to provide secure remote access. Two zero-day vulnerabilities — CVE-2026-83548 and CVE-2026-83549 — have been confirmed as actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Work Place interface, caused by an unintended alternate access path, carrying a CVSS score of 10.0. It allows a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations without any credentials. CVE-2026-83549 is a post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), with a CVSS score of 7.8, that allows a remote authenticated administrator to execute arbitrary OS commands.

When chained, CVE-2026-83548 provides the unauthenticated access path and CVE-2026-83549 delivers full remote code execution — together enabling unauthenticated RCE on the affected appliance. SonicWall has confirmed it investigated a case indicating active exploitation of the combination. The flaws affect SMA1000 models 6210, 7210, and 8200v running firmware versions 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier. Fixed platform-hotfix builds are 12.4.3-03526 and 12.5.0-02952. This follows a prior chained zero-day campaign against the same product line in July 2026, targeting CVE-2026-15409 and CVE-2026-15410 — further establishing SMA1000 as a persistently targeted high-value network edge device.

Why should TPRM professionals care?

SMA1000 appliances sit at the network edge as enterprise VPN gateways — a pre-authentication vulnerability against these devices exposes the front door of corporate networks to unauthenticated remote attackers. A successful exploit chain grants arbitrary code execution on the appliance itself, with potential for lateral movement into all connected corporate and government networks. Shodan data identified over 1,600 potentially vulnerable SMA1000 instances exposed to the internet across affected firmware versions. CISA's KEV listing signals the highest remediation urgency for federal agencies, but private sector TPRM professionals should treat it equivalently given confirmed active exploitation. SonicWall recommends organizations contact Technical Support to review IoCs — and if compromise is confirmed, full re-imaging or re-deployment is required alongside complete credential rotation.

What questions should TPRM professionals ask vendors?

  1. Have you applied SonicWall platform-hotfix 12.4.3-03526 or 12.5.0-02952 to all SMA1000 series appliances (models 6210, 7210, and 8200v)?
  2. If immediate patching is not possible, have you disabled Appliance Management Console (AMC) and SSH access from the public internet, restricting them to VPN tunnels or trusted internal IP addresses only?
  3. Have you contacted SonicWall Technical Support to review your SMA1000 appliances for indicators of compromise, given that SonicWall has confirmed active exploitation in the wild?
  4. If indicators of compromise are confirmed, have you re-imaged (hardware) or re-deployed (virtual) the affected appliances, changed all user and administrator passwords, and reset all TOTP tokens?
  5. Are your SMA1000 management interfaces restricted to trusted internal networks or VPN tunnels, or are they directly accessible from the public internet?

Remediation recommendations

  • Apply platform-hotfix 12.4.3-03526 or 12.5.0-02952 to all SMA1000 series appliances (models 6210, 7210, and 8200v) immediately; upgrades are available from mysonicwall.com.
  • Until patching is complete, disable AMC and SSH access from the public internet and restrict them exclusively to VPN tunnels or specific trusted internal IP addresses to reduce the attack surface.
  • Contact SonicWall Technical Support to conduct an IoC review on all affected appliances; if IoCs are found, re-image or re-deploy the device and rotate all user, administrator, and TOTP credentials immediately.
  • Review network segmentation around SMA1000 appliances and monitor system and network logs for unauthorized access attempts, unusual traffic patterns, or signs of lateral movement from the affected devices.
Black Kite’s SonicWall SMA1000 - Aug2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite’s SonicWall SMA1000 - Aug2026 FocusTag® details critical insights on the event for TPRM professionals.

Sangoma Switchvox (CVE-2026-9586)

What is this vulnerability?

Sangoma Switchvox SMB Edition is an enterprise VoIP telephony management platform used by organizations to configure phone systems, voicemail, call routing, and call analytics. CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in the /pa HTTP endpoint, which processes XML-formatted phone notification requests from VoIP phones without requiring authentication. The PhoneIP field extracted from attacker-controlled XML is directly concatenated into a PostgreSQL query without any sanitization or parameterization. Because the backend PostgreSQL process runs with superuser privileges, an attacker can leverage PostgreSQL's COPY TO PROGRAM functionality to execute arbitrary OS commands — achieving full remote code execution with a single crafted HTTP POST request and no credentials required.

The vulnerability was first disclosed by Security Risk Advisors on July 17, 2026 and added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026. Horizon3's honeypot telemetry confirms that automated, large-scale exploitation began on August 30, 2026, with multiple instances targeted in rapid succession from the same source IP — indicating that weaponized scanning tooling is already actively deployed. Public proof-of-concept exploits are available. Observed post-exploitation tradecraft includes reverse shell establishment via netcat and base64-encoded reconnaissance commands exfiltrated to attacker-controlled servers. Evidence of exploitation is logged in /var/log/switchvox/db-quirks.log. Approximately 4,000 Switchvox devices are exposed on the internet, predominantly in the United States. The vulnerability affects Switchvox SMB Edition versions 8.3 (104997) through 8.4.0.1 and is fully remediated in version 8.4.0.2, released July 14, 2026.

Why should TPRM professionals care?

VoIP telephony management systems hold uniquely sensitive operational data — call records, voicemail content, extension configurations, authentication credentials, and potentially integration tokens for connected enterprise systems. CVE-2026-9586 requires no authentication and no prior knowledge of the target; a single HTTP POST request is sufficient to gain full database and OS command access. The PostgreSQL superuser execution context means the attacker has complete read, write, and execute capability across the entire Switchvox database without any privilege escalation step. Horizon3's observation that exploitation attempts began from the same source IP across multiple honeypots confirms that automated mass exploitation infrastructure is already operational — meaning every internet-exposed Switchvox instance running a vulnerable version should be assumed targeted. The patch (version 8.4.0.2) was released July 14, 2026 — nearly seven weeks before CISA's KEV listing — yet exploitation is now actively underway, underscoring the urgency of verifying patch status across vendor environments.

What questions should TPRM professionals ask vendors

  1. Have you upgraded all Sangoma Switchvox SMB Edition deployments to version 8.4.0.2, the only complete remediation for CVE-2026-9586?
  2. Have you blocked all external internet access to the Switchvox Application Server at the network perimeter, restricting the /pa endpoint and all web access to trusted internal IP ranges?
  3. Have you inspected /var/log/switchvox/db-quirks.log for SQL injection payloads consistent with CVE-2026-9586 exploitation, such as COPY (SELECT) TO PROGRAM, netcat reverse shell commands, or connections to external IP addresses?
  4. Have you reviewed network and firewall logs for connections to or from known attacker IPs or other unexpected external hosts communicating with the Switchvox server?
  5. If exploitation is confirmed, are you initiating a full rebuild from a clean backup and rotating all VoIP credentials, database passwords, and secrets accessible from the compromised host, rather than attempting in-place remediation?

Remediation recommendations

  • Upgrade all Sangoma Switchvox SMB Edition deployments to version 8.4.0.2 immediately; given the CISA KEV listing and Horizon3-confirmed automated exploitation, every internet-accessible instance running a vulnerable version should be assumed targeted.
  • Block all external internet access to the Switchvox Application Server at the firewall or network perimeter as an urgent interim measure; the /pa endpoint requires no authentication and can be reached by any external actor with network access.
  • Inspect /var/log/switchvox/db-quirks.log for exploitation evidence including COPY (SELECT) TO PROGRAM, reverse shell payloads, netcat commands, or connections to external IPs; treat any confirmed entry as a high-priority incident requiring immediate escalation.
  • If compromise is confirmed, initiate a complete rebuild from a clean backup rather than in-place remediation; rotate all VoIP system credentials, database passwords, and any other secrets stored on or accessible from the Switchvox host.
Black Kite’s Sangoma Switchvox FocusTag® details critical insights on the event for TPRM professionals.

Black Kite’s Sangoma Switchvox FocusTag® details critical insights on the event for TPRM professionals.

MongoDB BI Connector (CVE-2026-75159, CVE-2026-755739)

What is this vulnerability?

MongoDB Connector for BI (mongosqld) is a middleware component that enables SQL-based business intelligence tools such as Tableau and Power BI to query MongoDB databases using standard SQL syntax. MongoDB has patched two vulnerabilities in the BI Connector in version 2.14.30. CVE-2026-75159 is a high-severity denial-of-service vulnerability in which a crafted Kerberos (GSSAPI) authentication exchange triggers an improper memory-handling condition that terminates the shared mongosqld process, cutting BI reporting service for all connected SQL clients. The vulnerability can be triggered by an unauthenticated client on instances where Kerberos authentication is enabled. CVE-2026-75573 is a medium-severity information-disclosure flaw in which mongodrdl writes a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option — potentially exposing cryptographic credentials in log output.

Both vulnerabilities affect MongoDB Connector for BI versions 2.4.0 (and 2.12.0) through 2.14.29 and are fully remediated in version 2.14.30, released July 22, 2026. Neither vulnerability has confirmed active exploitation in the wild, and neither is listed in CISA's Known Exploited Vulnerabilities catalog. No public proof-of-concept exploits have been reported for either flaw. Approximately 238 vulnerable BI Connector instances were identified via Shodan across affected versions. These two BI Connector flaws were disclosed as part of a broader MongoDB advisory round that also included ten CVEs in official MongoDB language drivers; those driver-side flaws affect a different component and are out of scope for this tag.

Why should TPRM professionals care?

MongoDB BI Connector serves as the bridge between MongoDB databases and SQL-based analytics and reporting tools — a component that sits in the data path of business intelligence workflows and may have access to sensitive organizational datasets. CVE-2026-75159 allows any network-accessible attacker to crash the shared mongosqld process on Kerberos-enabled deployments, terminating BI reporting service for all connected clients and potentially disrupting analytics-dependent business operations. CVE-2026-75573's credential disclosure risk is more constrained — it requires log access — but TLS private-key exposure is a meaningful risk in environments where log aggregation infrastructure may be shared or externally accessible. While neither flaw carries the immediate active-exploitation urgency of this week's other tags, TPRM professionals should verify that vendors running MongoDB-based analytics pipelines have applied the available patch and have appropriately restricted mongosqld network exposure.

What questions should TPRM professionals ask vendors?

  1. Have you identified all MongoDB Connector for BI (mongosqld) instances in your environment and confirmed they are running version 2.14.30 or later?
  2. Is mongosqld deployed behind a firewall or VPN, with access restricted to trusted BI client IP addresses rather than exposed to untrusted internal or external networks?
  3. Have you reviewed mongosqld and mongodrdl log output (stderr) for any cleartext TLS private-key passwords that may have been logged by versions prior to 2.14.30?
  4. Have you rotated any TLS key passwords that may have been disclosed in log files from BI Connector deployments running affected versions?
  5. Do you have an automated patch management process for MongoDB BI Connector updates to ensure future security advisories are applied promptly?

Remediation recommendations

  • Upgrade MongoDB Connector for BI (mongosqld) to version 2.14.30 or later to remediate both CVE-2026-75159 and CVE-2026-75573; this is the vendor's complete fix for both vulnerabilities.
  • Restrict mongosqld network exposure by placing it behind a firewall or VPN and limiting access exclusively to trusted BI clients on internal networks; mongosqld should not be directly accessible from untrusted networks.
  • Review log output (stderr) from all mongosqld and mongodrdl deployments running affected versions for cleartext TLS private-key password entries, and rotate any credentials that may have been exposed.
  • Establish an automated patch management workflow for MongoDB BI Connector to ensure future security updates are applied promptly and inventory of running versions is regularly audited.
Black Kite’s MongoDB BI Connector FocusTag® details critical insights on the event for TPRM professionals.

Black Kite’s MongoDB BI Connector FocusTag® details critical insights on the event for TPRM professionals.

How TPRM Professionals Can Leverage Black Kite for These Vulnerabilities

Black Kite's platform automatically identifies vendors in your third-party portfolio that are running PaperCut MF/NG, SonicWall SMA1000, Sangoma Switchvox, or MongoDB BI Connector at vulnerable versions — without requiring any manual research or vendor self-disclosure. When a FocusTag® is activated, it appears directly on affected vendor scorecards, giving TPRM teams an immediate, portfoliowide view of which third parties require urgent engagement. For this week's actively exploited tags, Black Kite surfaces the specific context TPRM teams need to prioritize correctly: PaperCut's Release 2 patch requirement (not just any patch), SonicWall's CISA KEV status and confirmed exploitation, Sangoma Switchvox's mass-exploit campaign already underway, and MongoDB's lower-urgency but actionable credential and availability risks. Each tag comes with structured vendor engagement questions tailored to the exact remediation and forensic actions required — enabling TPRM teams to move immediately from detection to vendor outreach without building questionnaires from scratch. TPRM professionals can use Black Kite's platform to filter their entire vendor portfolio by FocusTag® to generate a prioritized list of vendors requiring immediate contact, track remediation status as vendors confirm patch deployment, and document risk acceptance decisions for vendors unable to remediate within acceptable timelines. The Bridge connector further automates this workflow by enabling automated questionnaire dispatch directly to affected vendors — turning FocusTag® intelligence into actionable third-party risk management at scale across the full vendor portfolio.

Strengthening TPRM Outcomes with Black Kite’s FocusTags®

This week's four FocusTags® illustrate the breadth and depth of the Black Kite platform's ability to surface high-impact vendor risk events across diverse technology domains — from print management and VPN gateways to VoIP systems and database connectors. Each tag translates raw vulnerability intelligence into structured, actionable TPRM assessment and vendor engagement guidance.

•  Zero-Day Exploit Chain Detection: PaperCut's two-CVE chain — authentication bypass enabling unsafe class loading RCE — and SonicWall's SSRF-to-OS-command-injection chain each required understanding the combined attack path, not just individual CVE scores. FocusTags® analyze chained exploit sequences to surface the true operational risk, including the critical detail that PaperCut's first emergency patch was proven bypassable, requiring specific confirmation of Release 2 installation.

•  CISA KEV Alignment and Urgency Calibration: SonicWall and Sangoma Switchvox were both added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026. FocusTags® incorporate KEV status alongside Shodan exposure data and exploitation confirmation to assign the highest remediation urgency — ensuring TPRM teams engage vendors on the most critical events first, with timelines that match real-world threat actor activity rather than vendor advisory publication dates.

•  Automated Exposure Discovery via Shodan: Each of this week's tags was validated against Shodan telemetry to quantify internet-exposed instances at specific vulnerable firmware and software versions. Over 1,600 SMA1000 appliances at vulnerable firmware builds, approximately 4,000 Switchvox devices at risk, and 238 exposed BI Connector instances were identified — enabling Black Kite to detect which vendors in your third-party portfolio are running affected components without requiring vendor self-disclosure.

•  Differentiated Urgency Across a Mixed Threat Week: This week spans the full spectrum from actively exploited zero-days (PaperCut, SonicWall) and mass-exploit campaigns (Sangoma Switchvox) to patched-but-not-yet-exploited vulnerabilities (MongoDB BI Connector). FocusTags® provide differentiated prioritization signals for each threat profile, allowing TPRM teams to focus immediate engagement on PaperCut and SonicWall while scheduling routine verification for MongoDB without treating all four as equal urgency.

•  Structured Vendor Engagement Questions: Each FocusTag® generates vendor engagement questions tailored to the specific exploitation path and remediation requirements of each vulnerability — from PaperCut's Release 2-specific patch confirmation and IoC log review, to SonicWall's IoC-driven re-imaging requirement, Switchvox's db-quirks.log forensic review, and MongoDB's credential rotation and log audit. Generic patch-applied questions are insufficient for this week's events; FocusTags® ensure the right questions are asked.

•  Automated Vendor Scoring: FocusTags® automatically update vendor risk scores across the Black Kite platform for all third parties detected with internet-accessible PaperCut servers, SonicWall SMA1000 appliances, Sangoma Switchvox deployments, or MongoDB BI Connector instances at vulnerable versions — providing immediate risk signal updates across your entire vendor portfolio without manual assessment effort.

•  TPRM-Contextualized Analysis Beyond Patch Status: Each FocusTag® extends assessment beyond simple patch verification to evaluate the full third-party breach scenario — including whether PaperCut organizations applied the right patch version, whether SonicWall organizations have performed the required IoC review and credential rotation, whether Switchvox logs show active exploitation evidence, and whether MongoDB environments have addressed potential credential exposure in log files. This depth of assessment is what transforms raw vulnerability data into actionable TPRM intelligence.

About Focus Friday

Every week, we delve into the realms of critical vulnerabilities and their implications from a Third-Party Risk Management (TPRM) perspective. This series is dedicated to shedding light on pressing cybersecurity threats, offering in-depth analyses, and providing actionable insights.

FocusTags® in the Last 30 Days

  • PaperCut MF/NG - Aug2026: CVE-2026-81578, CVE-2026-82078, Unauthenticated Authentication Bypass via Apache Tapestry Dual-Page Request Format Enabling Unsafe Class Loading Remote Code Execution in PaperCut MF and NG (Emergency Patch Release 2 Required).
  • SonicWall SMA1000 - Aug2026: CVE-2026-83548, CVE-2026-83549, Pre-Authentication SSRF and OS Command Injection Zero-Day Chain Enabling Unauthenticated Remote Code Execution on SonicWall SMA1000 Secure Access Gateways (CISA KEV, Actively Exploited).
  • Sangoma Switchvox: CVE-2026-9586, Unauthenticated SQL Injection via /pa Endpoint Enabling PostgreSQL Superuser OS Command Execution in Sangoma Switchvox SMB Edition (CISA KEV, Mass-Exploit Campaign Active).
  • MongoDB BI Connector: CVE-2026-75159, CVE-2026-75573, Kerberos-Triggered Denial of Service and TLS Private-Key Password Disclosure in MongoDB Connector for BI (mongosqld).
  • TrueConf - Aug2026: CVE-2026-72529, CVE-2026-72530, Unauthenticated Pre-Authentication Remote Code Execution via Chained Missing Authentication and Sandbox Escape Vulnerabilities in TrueConf Server, Actively Exploited by Head Mare APT (CISA KEV).
  • OpenSSL - Aug2026: CVE-2026-18798, CVE-2026-63072, CVE-2026-63076, and 6 additional CVEs, Denial-of-Service and AEAD Authentication Tag Bypass Vulnerabilities in QUIC, CMS, CMP, DTLS, RPK, and AEAD Components of OpenSSL.
  • Apache Tomcat - Aug2026 (Latest): CVE-2026-65182, CVE-2026-68525, CVE-2026-68569, CVE-2026-65637, and 7 additional CVEs, Multiple Authentication and Authorization Bypass Vulnerabilities in Apache Tomcat Affecting 187,461 Exposed Internet-Facing Services.
  • PostgreSQL - Aug2026: CVE-2026-14669, Heap-Based Buffer Overflow in to_char(timestamptz) Enabling Authenticated Remote Code Execution as OS User in PostgreSQL (Public PoC Available).
  • WordPress Elementor - Aug2026: CVE-2026-32475, Unauthenticated Arbitrary File Upload to Remote Code Execution via Loop Desynchronization in Elementor Pro WordPress Plugin (Mass-Exploit Campaigns Active).
  • Citrix NetScaler - Aug2026: CVE-2026-8452, Pre-Authentication Memory Overflow in SAML Signature Canonicalization enabling Remote Code Execution as Root in NetScaler ADC and NetScaler Gateway.
  • VMware vCenter - Aug2026: CVE-2026-59309, CVE-2026-59310, Authentication Bypass in VMware Directory Service and Directory Traversal RCE in vCenter Syslog Server enabling Unauthenticated Full vCenter Takeover.
  • Zimbra - Aug2026: CVE-2026-73570, Unauthenticated SNMP Command Injection enabling Arbitrary OS Command Execution as zimbra User in Zimbra Collaboration Suite.
  • Oracle WebLogic - Aug2026: CVE-2026-60702, and 7 additional CVEs (CVSS up to 9.9), Multiple Unauthenticated Remote Code Execution and Takeover Vulnerabilities via T3 and IIOP in Oracle WebLogic Server.
  • Roundcube - Aug2026: No CVE, Remote Code Execution via markasjunk Plugin cmd_learn Driver and Server-Side Request Forgery Bypass Vulnerabilities in Roundcube Webmail.
  • Water Sector Campaign: CVE-2017-16740, Active Cyber Campaign Targeting Internet-Facing Rockwell MicroLogix PLCs Causing Operational Disruptions at U.S. Water and Wastewater Utilities.
  • Metabase: CVE-2026-72898, Unauthenticated SQL Injection via /api/session/reset_password enabling Full Administrator Takeover in Metabase Business Intelligence Platform.
  • Cisco ASA & FTD - Aug2026: CVE-2026-20349, Unauthenticated Denial of Service via Crafted HTTP Request to Remote Access SSL VPN Service in Cisco Secure Firewall ASA and FTD.
  • Cisco IMC - Aug2026: CVE-2026-20200, CVE-2026-20288, Argument Injection via SSH Public Key Retrieval Feature enabling Low-Privilege to Root Escalation in Cisco Integrated Management Controller.
  • Cisco IOS XE - Aug2026: CVE-2026-20272, CVE-2026-20267, and 5 additional CVEs, Multiple Critical and High-Severity Vulnerabilities including Command Injection and Authentication Bypass in Cisco IOS XE Software.
  • Adobe ColdFusion - Aug2026: CVE-2026-48362, and 14 additional CVEs (CVSS up to 10.0), Multiple Critical Remote Code Execution and Deserialization Vulnerabilities in Adobe ColdFusion.
  • SharePoint - Aug2026: CVE-2026-63520, CVE-2026-66808, and 13 additional CVEs, Multiple Deserialization and Unauthenticated Remote Code Execution Vulnerabilities in Microsoft SharePoint Server.
  • Exchange Server - Aug2026: CVE-2026-62912, CVE-2026-65813, and 5 additional CVEs, Multiple Remote Code Execution and Privilege Escalation Vulnerabilities in Microsoft Exchange Server.
  • ClamAV - Aug2026: CVE-2026-20337, CVE-2026-20338, and 5 additional CVEs, Multiple ZIP Parser and File Processing Denial of Service Vulnerabilities in ClamAV Antivirus Engine.
  • pgAdmin - Aug2026: CVE-2026-17566, CVE-2026-17349, CVE-2026-17351, CVE-2025-13780, CVE-2026-12045, Remote Code Execution via Unsafe Deserialization and Multiple Critical Vulnerabilities in pgAdmin 4.
  • Django - Aug2026: CVE-2026-15307, CVE-2026-15920, CVE-2026-15337, CVE-2026-15830, Remote Code Execution and Multiple High-Severity Vulnerabilities in Django Web Framework.
  • Jenkins - Aug2026: CVE-2026-70426, JEP-200 Deserialization Filter Bypass enabling Remote Code Execution in Jenkins Automation Server.
  • TeamCity - Jul2026: CVE-2026-63077, Unauthenticated Authentication Bypass via Agent Polling Protocol leading to Remote Code Execution in JetBrains TeamCity On-Premises.
  • Cisco FMC - Jul2026: CVE-2026-20316, CVE-2026-20079, Static Credential Authentication Bypass and Critical Authentication Bypass (CVSS 10.0) leading to Root Execution in Cisco Secure Firewall Management Center.
  • SolarWinds WHD - Aug2026: CVE-2026-28323, CVE-2026-28299, SAML Authentication Bypass and Denial of Service Vulnerability in SolarWinds Web Help Desk.
  • N-central - Aug2026: CVE-2026-18577, CVE-2026-18556, Authentication Bypass via Alternate Path leading to Full Account Takeover and RMM-Level Access in N-able N-central.
  • Langflow - Aug2026: CVE-2026-9198, Unauthenticated Superuser Token Minting via /api/v1/auto_login enabling Remote Code Execution in Langflow.
  • Apache Tomcat - Aug2026: CVE-2026-34486, CVE-2026-29146, EncryptInterceptor Bypass enabling Unauthenticated Remote Code Execution via Java Deserialization in Apache Tomcat Clustering.
  • Gitea - Aug2026: CVE-2026-59774, Org-mode #+INCLUDE Path Traversal enabling Arbitrary File Read and Remote Code Execution in Gitea.
  • WordPress - wp2shell : CVE-2026-63030, CVE-2026-60137, REST API Batch-Route Confusion Vulnerability and SQL Injection Vulnerability Leading to Unauthenticated Remote Code Execution in WordPress Core.

See Black Kite's full CVE Database and the critical TPRM vulnerabilities that have an applied  FocusTags® at https://blackkite.com/cve-database.

References

https://www.cve.org/CVERecord?id=CVE-2026-82078

https://www.cve.org/CVERecord?id=CVE-2026-81578

https://www.papercut.com/kb/Main/Security-Bulletin-27-Aug-2026

https://securityonline.info/papercut-zero-day-cve-2026-82078/

https://github.com/rapid7/metasploit-framework/pull/21842

https://www.cve.org/CVERecord?id=CVE-2026-83548

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

https://www.cve.org/CVERecord?id=CVE-2026-83549

https://www.helpnetsecurity.com/2026/09/02/sonicwall-sma-1000-cve-2026-83548-cve-2026-83549-zero-day-attacks/

https://securityonline.info/sonicwall-sma1000-cve-2026-83548-ssrf/

https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html

https://www.cve.org/CVERecord?id=CVE-2026-9586

https://www.horizon3.ai/attack-research/attack-blogs/discovering-and-observing-active-exploitation-of-sangoma-switchvox-cve-2026-9586/

https://labs.sra.io/posts/switchvox/

https://nvd.nist.gov/vuln/detail/CVE-2026-75159

https://nvd.nist.gov/vuln/detail/CVE-2026-75573

https://www.mongodb.com/docs/bi-connector/current/release-notes/

https://www.mongodb.com/resources/products/alerts

https://securityonline.info/mongodb-security-vulnerabilities/