CVE-2026-83549

6 karet z 12 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-83549

KEV ✓ EPSS 0.09 EPSS k 20. 9. 2026 náprava do 5. 9. 2026

Hodnocení závažnosti

7.8 CVSS 3.1 CISA-ADP

útok z místního přístupu bez přípravy stačí běžný účet bez zásahu uživatele
dopad plný únik dat úplná změna dat úplný výpadek
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

Hvězdička u CVE znamená, že radar to číslo vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí — u té zprávy proto neukazuje KEV, EPSS ani CVSS. Fakta o samotném CVE jsou nahoře.

1

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!New module content (16)Elasticsearch ingest-attachment Apache Tika XFA XXE Local File ReadAuthors: Bourbon Offensive Security Services and Jean-Marie BourbonType: AuxiliaryPull request: #21739…

KEV ✓ EPSS 0.88 CVE-2025-54988 CVE-2025-66516 CVE-2026-19295 CVE-2026-20079 CVE-2026-20929 CVE-2026-23744 CVE-2026-48558 CVE-2026-63077 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 CVE-2026-83548 CVE-2026-83549 Cisco PaperCut SonicWall JetBrains US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: This One Goes to Sixteen!

1

7th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information. Hit, a major Slovenian gambling and tourism…

KEV ✓ EPSS 0.09 CVSS 10.0 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 Thomson Reuters Dropbox SonicWall JFrog IL

tg: přehled tp: malware tp: ransomware tp: únik dat tp: AI

· Check Point Research · 7th September – Threat Intelligence Report

1

SPOJENO PŘES CVE SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…

KEV ✓ EPSS 0.09 CVSS 10.0 CVE-2026-83548 CVE-2026-83549 SonicWall FI US CA IT AT FR

tg: zneužíváno tg: zranitelnost

· NCSC-FI · SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10 · Rapid7 · Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild · Cyber Centre Kanada · SonicWall security advisory (AV26-872) · CSIRT Itálie (ACN) · SonicWall: rilevato sfruttamento in rete delle CVE-2026-83548 e CVE-2026-83549 · CERT.at · Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar · CERT-FR – avis · Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)

3

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

KEV ✓ EPSS 0.36 CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 CVE-2026-9586 Sangoma JFrog SonicWall BerriAI veřejná správa US

tg: zneužíváno tg: zranitelnost

· CISA Advisories · CISA Adds Seven Known Exploited Vulnerabilities to Catalog