Week Ending: September 6, 2026 | Overall Risk Posture: Critical
CISA added ten vulnerabilities to its Known Exploited Vulnerabilities catalog during the week ending September 6: two PaperCut flaws on August 31, seven additions on September 2, and an exploited Chrome zero-day on September 4.
The products span print management, AI gateways, Python web infrastructure, workflow orchestration, artifact repositories, business telephony, remote-access appliances, and browsers. But the strongest signal is not the variety. It is the number of familiar names.
PaperCut, LiteLLM, JFrog Artifactory, and SonicWall have all appeared in recent exploitation activity. This week, each returned with a different weakness. That changes the operational question from “Did we patch the last CVE?” to “Why does this platform remain reachable, privileged, and difficult to investigate every time the next flaw arrives?”
Threat at a Glance
| Product | KEV | Why It Matters |
|---|---|---|
| PaperCut NG/MF | CVE-2026-81578 / CVE-2026-82078 | An authentication bypass and unsafe class-loading flaw can be chained for unauthenticated code execution on the print server. |
| BerriAI LiteLLM | CVE-2026-59822 | A fabricated bearer token can bypass authentication on the MCP Streamable HTTP endpoint in versions before 1.84.0. |
| Starlette | CVE-2026-48710 | A malformed Host header can make security checks inspect a different path from the one actually routed. |
| Kestra OSS | CVE-2026-49869 | A loose path-suffix check can bypass authentication and let a remote attacker create and execute workflows. |
| JFrog Artifactory | CVE-2026-82329 | A critical authentication weakness can provide administrative access under the default configuration. |
| Sangoma Switchvox | CVE-2026-9586 | Unauthenticated SQL injection leads to remote code execution on an on-premises business phone system. |
| SonicWall SMA1000 | CVE-2026-83548 / CVE-2026-83549 | SSRF and OS command injection return attention to an appliance family already represented in KEV this summer. |
| Google Chrome | CVE-2026-85046 | A V8 type-confusion flaw has an exploit in the wild; Chrome must be updated and relaunched to load the fixed build. |
The Strongest Story: Remediation Without Resilience
A KEV entry is normally handled as a vulnerability ticket: identify affected versions, apply the vendor fix, confirm the version, and close the item. This week shows the limit of that model.
LiteLLM is back after earlier exploited SQL-injection and command-execution issues. Artifactory entered KEV last week for a path-traversal weakness and returned this week with a critical authentication bypass. SonicWall SMA1000 had two vulnerabilities added in July and now has two more. PaperCut is again under active exploitation after its widely exploited 2023 incident established print-management servers as useful entry points.
The individual patches are still mandatory. The failure is treating each patch as the end of the risk. These platforms often hold credentials, run with elevated privileges, expose administrative interfaces, or connect directly to internal systems. When the same product family repeatedly appears in active exploitation, defenders need a product-level control plan: reduce exposure, restrict management access, centralize logs away from the appliance, maintain an owner and emergency update path, and predefine what evidence must be reviewed after exploitation is confirmed.
The operating-model problem: Closing one CVE ticket proves that one patch was applied. It does not prove the platform is minimally exposed, externally logged, rapidly patchable, or ready for investigation when the next vulnerability arrives.
PaperCut: Two Flaws Become One Critical Attack
The two PaperCut vulnerabilities are the clearest example of why flaws should be evaluated as an attack path, not only as separate scores.
- The first flaw opens the configuration boundary
CVE-2026-81578 allows specially crafted unauthenticated requests to reach administrative backend actions before access checks finish. By itself, it permits changes to selected system configuration. - The second flaw turns configuration access into code execution
CVE-2026-82078 lets PaperCut load a database driver class named in configuration without restricting it to an approved list. That flaw normally requires control over configuration. The first vulnerability supplies it.
Chained together, the pair can produce unauthenticated Java code execution under the PaperCut server process. PaperCut’s advisory says every version of PaperCut NG and MF is potentially affected and directs customers to its emergency patches.
The vendor also published unusually useful investigation detail. Indicators include missing or truncated server.log files, suspicious database-driver errors, unexpected .class, .cmd, or .out files under the PaperCut installation, and the pc-app process launching a shell. Observed activity included host and domain discovery followed by installation of a SimpleHelp remote-access agent.
Immediate action: If an internet-reachable PaperCut server was exposed before the emergency patch, preserve and review its logs before an attacker—or a routine upgrade—removes evidence. Treat it as an investigation event, not just a version check.
Authentication Failed at Several Layers
PaperCut is not an isolated authentication story. Four other additions show different ways a system can appear protected while an attacker reaches the privileged function behind it.
- LiteLLM: a fabricated token reached MCP tooling
CVE-2026-59822 allowed the MCP Streamable HTTP endpoint to accept a fabricated bearer token after an OAuth2 passthrough failure. The fix is LiteLLM 1.84.0. Organizations should inventory MCP endpoints specifically and review tool calls and key use during the exposure window. - Starlette: security checks saw the wrong path
CVE-2026-48710 arose because routing used the raw request path while some middleware reconstructedrequest.urlfrom an attacker-controlled Host header. Security logic could approve one apparent path while the server routed another. Starlette 1.0.1 contains the fix. - Kestra: a suffix check opened the workflow engine
CVE-2026-49869 involved an authentication filter usingendsWith("/configs")to identify a public endpoint. A crafted API path with the same suffix could bypass authentication, allowing creation and execution of arbitrary workflows. Fixed releases include 1.0.45 and 1.3.21. - Artifactory: authentication bypass reached administrator privileges
CVE-2026-82329 is a critical authentication weakness that can yield administrative access under the default configuration. Because Artifactory governs trusted packages and build inputs, administrative compromise is also a software-supply-chain concern.
The common failure is authorization based on an assumption that the request has already been correctly identified: the right token, path, route, or internal context. Defenders cannot repair those code paths themselves, but they can reduce the blast radius by keeping administrative and orchestration interfaces off the public internet and requiring a separate network access control before the application’s own authentication.
Switchvox and SonicWall Keep the Edge Under Pressure
CVE-2026-9586 affects Sangoma Switchvox and turns one crafted unauthenticated request into SQL execution against the backend PostgreSQL database. Horizon3.ai, which reported the flaw, says it can lead to remote code execution and observed valid exploitation attempts on August 30. Sangoma patched the issue in Switchvox 8.4.0.2.
The SonicWall additions—SSRF in CVE-2026-83548 and OS command injection in CVE-2026-83549—matter partly because they affect a remote-access appliance and partly because SMA1000 is returning to KEV after two July additions. Apply SonicWall’s SNWLID-2026-0016 guidance, restrict management access, and retain logs outside the appliance.
Chrome Is the Broadest Immediate Exposure
Google’s September 3 desktop update fixed 12 security issues, including CVE-2026-85046, a high-severity type-confusion flaw in the V8 JavaScript engine. Google explicitly states that an exploit exists in the wild.
Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux contain the fix. Because browser updates can be downloaded without replacing an already running process, security teams should measure the active browser version after relaunch—not only whether the update package reached the endpoint.
Defender Priorities
- Patch PaperCut and investigate exposure
Apply the emergency release, preserveserver.log, hunt for PaperCut’s published indicators, and review child processes and newly installed remote-access services. - Update and relaunch Chrome
Verify the running version across managed endpoints, including browsers embedded in managed desktop environments. - Remove administrative interfaces from direct internet reach
Prioritize PaperCut, LiteLLM and MCP, Kestra, Artifactory, Switchvox, and SonicWall management surfaces. - Treat repeat KEV products as a control problem
Assign a named owner, emergency update method, external log retention, exposure monitoring, and investigation checklist for each repeatedly affected platform. - Review privileged activity, not just versions
For Artifactory, inspect administrator creation, token issuance, repository changes, and artifact publishing. For LiteLLM and Kestra, review tool calls, workflow creation, secrets access, and unusual outbound connections. - Validate remediation from outside
Confirm that services no longer intended for public access are unreachable, and verify the fixed build on the actual running instance.
Bottom Line
This week’s ten KEV additions are not ten isolated patch tickets. They show attackers returning to the same high-leverage platforms with new ways around trust boundaries.
PaperCut demonstrates how two flaws become a pre-authentication attack chain. LiteLLM, Artifactory, and SonicWall demonstrate why closing one CVE does not make an exposed platform resilient. Chrome adds the broad endpoint risk that must be handled immediately.
Patch the vulnerabilities. Then fix the recurring condition: privileged software that remains broadly reachable, weakly monitored, and treated as safe again the moment the last ticket closes.
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — Seven Known Exploited Vulnerabilities Added, September 2, 2026
- CISA — Google Chromium V8 Vulnerability Added, September 4, 2026
- PaperCut — Urgent NG/MF Security Bulletin
- GitHub Advisory — LiteLLM MCP Authentication Bypass
- GitHub Advisory — Starlette Host-Header Validation Vulnerability
- Kestra — Unauthenticated Workflow Execution Advisory
- JFrog — Artifactory Security Advisories
- Horizon3.ai — Sangoma Switchvox SQL Injection to RCE
- SonicWall PSIRT — SNWLID-2026-0016
- Google Chrome — Stable Channel Update for Desktop

