September 3, 2026 | Jonathan Brown
Command View
Reporting cutoff: September 3, 2026, 14:10 UTC
Priority posture: RED
Operational focus: internet-facing control planes, trusted software-delivery paths, judicial data suppliers, government geospatial services, and physical electricity infrastructure.
Seven vulnerabilities were added to the U.S. Known Exploited Vulnerabilities catalog after the previous briefing's cutoff. Five now carry a September 5 federal remediation deadline; Starlette CVE-2026-48710 and LiteLLM CVE-2026-59822 carry a September 16 deadline. The action compresses response time for two SonicWall SMA1000 flaws, Sangoma Switchvox, JFrog Artifactory, Kestra, Starlette, and LiteLLM. The deadlines bind U.S. Federal Civilian Executive Branch agencies; other operators should treat them as high-confidence prioritization signals, not as a legal mandate.
Today's strongest cross-sector pattern is compromise of management and orchestration layers rather than isolated endpoints. The affected products broker remote access, voice systems, software artifacts, AI tools, workflows, virtualization updates, court records, and geospatial services. A successful intrusion at any one of these layers can transfer trust into downstream systems, credentials, workloads, or data.
This briefing uses confirmed exploitation only where a vendor, government catalog action, or directly attributed researcher/operator observation supports it. Exposure scans are not compromise counts. Microsoft and other researchers' technical assessments are identified as assessments, not as proof of a specific exploit path. Actor attribution remains unestablished for the German infrastructure incidents, the Virtualizor operation, the C-Track intrusion, and the GeoNetwork research finding.
Status definitions
- RED: active exploitation or an immediate critical-system risk requiring same-shift action.
- AMBER: a material exposure or incident with a credible path to impact; prioritize in the current operating cycle.
- WATCH: incomplete, conflicting, or pre-exploitation evidence; monitor and pre-stage controls.
- CONTEXT: background that changes interpretation but does not independently require a new action.
Today's Decisions
- RED — Network, voice, and artifact owners: identify every SonicWall SMA1000, Switchvox, and self-hosted JFrog Artifactory instance; move each to the applicable fixed release; and conduct evidence-led compromise review. For covered federal assets that meet BOD 26-04's exposure, automation, and technical-impact criteria, remediation includes the required forensic triage—not patching alone.
- RED — AI, platform, and cloud teams: patch Kestra, Starlette, and LiteLLM immediately. Isolate any system showing unexpected workflow creation, MCP tool discovery, child shells, environment-secret access, or container reconnaissance; then rotate reachable credentials and connected-service tokens.
- RED — Hosting providers: treat a positive Virtualizor indicator as possible root compromise of the hypervisor. Preserve evidence, isolate the node, scope adjacent infrastructure, and rebuild from trusted media where integrity cannot be proved. Version
3.2.9.9is an available mitigation and analyzer release; it is not proof that a host is clean and does not retroactively authenticate packages delivered during the route hijack. - RED — Electricity operators and physical-security leads: sustain elevated monitoring and rapid inspection around substations, generation interconnects, rights of way, and nearby concealment areas. Germany's restoration progress reduces immediate capacity pressure, but the repeated delivery method and unresolved linkage keep the threat operationally significant.
- AMBER — Government and geospatial platform owners: patch GeoNetwork to
4.4.12or4.2.17. Until then, block unauthenticatedPOST,PUT, andPATCHrequests to/geonetwork/srv/api/formattersand review formatter content and application child processes. - AMBER — Courts, justice agencies, and supplier-risk teams: obtain tenant-specific facts from C-Track, preserve access and administrative logs, identify affected sealed or restricted data, and prepare targeted notice, identity-protection, and anti-phishing measures. The disclosure concerns file access, not a reported service outage.
- WATCH — OT asset owners: schedule the applicable Rockwell controller and FactoryTalk Historian ME firmware updates. Rockwell's ControlLogix advisory contains conflicting KEV fields; absent corroboration, this briefing does not label CVE-2026-9637 as exploited.
Threat and Resilience Ledger
RED — Global | Remote access, voice, and software delivery | Five exploited flaws move onto emergency timelines
What changed. On September 2, the U.S. government added both SonicWall SMA1000 flaws, Sangoma Switchvox CVE-2026-9586, and JFrog Artifactory CVE-2026-82329 to its exploited-vulnerability catalog. Their federal due date is September 5. That designation is new since the previous briefing and materially raises the priority of all three platforms.
SonicWall SMA1000. CVE-2026-83548 is a pre-authentication server-side request forgery flaw in WorkPlace that can make the appliance act as an unintended forward proxy. CVE-2026-83549 is post-authentication OS command injection available to an administrative user through the Appliance Management Console. SonicWall reports a customer case indicating active exploitation of both flaws. The evidence supports co-occurrence; it does not establish that the two were necessarily chained in every intrusion.
The affected SMA1000 models are 6210, 7210, and 8200v running 12.4.3-03453 and earlier on the 12.4 branch or 12.5.0-02835 and earlier on the 12.5 branch. Fixed releases are 12.4.3-03526 and 12.5.0-02952. Upgrade, retrieve SonicWall's indicators through the vendor support channel, and review administrative and WorkPlace activity. If compromise evidence exists, reimage or redeploy the appliance and rotate administrator and user passwords, reset TOTP enrollment, and invalidate reachable credentials.
Sangoma Switchvox. CVE-2026-9586 is an unauthenticated SQL-injection path in the /pa endpoint. An attacker-controlled PhoneIP value in a PolycomIPPhone XML body reaches a PostgreSQL query; database-superuser privileges can then be converted into OS command execution. Horizon3.ai reported valid exploitation attempts beginning August 30 and published an observed source address, 176.65.148[.]184, together with reverse-shell and process-enumeration behavior. The address is an indicator, not actor attribution.
Sangoma released Switchvox 8.4.0.2 on July 14. The research reproduced the flaw on Switchvox SMB Edition 8.3 build 104997; public evidence does not safely define every earlier 8.x build, so operators should inventory rather than infer. Move to 8.4.0.2 or later and inspect /var/log/switchvox/db-quirks.log, web requests to /pa, unusual database activity, and application-host child processes. Horizon3.ai's estimate of roughly 4,000 internet-visible systems is an exposure estimate, not a count of vulnerable or compromised systems.
JFrog Artifactory. CVE-2026-82329 is an authentication failure in the default configuration that can allow an unauthenticated network attacker to obtain administrative access. JFrog identifies fixed self-hosted releases 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20; JFrog Cloud was already fortified. Because the advisory's affected-range notation is easy to misread across parallel release branches, select the named fixed release for the deployed branch or a later vendor-supported build.
SecurityWeek's report of watchTowr telemetry says an operator minted administrative tokens and enumerated users, groups, credential sets, and federation information. That supports exploitation and reconnaissance. Public evidence reviewed by the cutoff does not establish mass exploitation, artifact poisoning, or downstream code execution. Patch, invalidate administrative and access tokens, review new principals and federation changes, validate repository integrity, and examine build and deployment systems that trusted the instance.
Operational consequence. These platforms sit at trust boundaries. Compromise can expose remote-access identities, telephony administration, proprietary artifacts, signing or deployment secrets, and connected production systems even when the vulnerable server itself remains available.
Evidence: vendor advisories and fixed releases; government exploited-vulnerability designation reported by an independent security publication; direct Horizon3.ai technical telemetry; attributed watchTowr observations reported by SecurityWeek.
Attribution: unknown. The published Switchvox IP and JFrog activity do not establish a named actor.
Confidence: high for vulnerability mechanics, fixed versions, KEV status, and exploitation; moderate for the full intrusion scope at affected organizations.
Uncertainty: victim counts, initial access at each victim, persistence, stolen data, and downstream artifact use remain unknown.
Sources: SonicWall PSIRT, “Unauthenticated SSRF and Post-Authentication OS Command Injection Vulnerabilities in SMA1000 Series” (accessed September 3, 2026); Horizon3.ai, “CVE-2026-9586: Sangoma Switchvox RCE” (September 2, 2026); Sangoma, “Switchvox — Release Notes Version 8.4.0.2” (July 14, 2026); JFrog, “JFrog Security Advisories,” CVE-2026-82329 entry (August 28, 2026); The Hacker News, “CISA Adds Seven Exploited Flaws as BOD 26-04 Sets Rapid Deadlines” (September 3, 2026); SecurityWeek, “Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild” (accessed September 3, 2026); CVE Program records for CVE-2026-83548, CVE-2026-83549, CVE-2026-9586, and CVE-2026-82329.
RED — Global | AI and workflow control planes | Three exploited flaws expose tools, secrets, and execution paths
What changed. Kestra CVE-2026-49869, Starlette CVE-2026-48710, and LiteLLM CVE-2026-59822 were added to the exploited-vulnerability catalog. Kestra carries the September 5 federal due date; Starlette and LiteLLM carry September 16. Separate Microsoft and Wiz observations provide operational context, but they should not be collapsed into one campaign.
Kestra. CVE-2026-49869, rated CVSS 10.0, stems from an authentication filter that accepted paths ending in /configs. In the affected Kestra OSS default basic-auth configuration, a network-reachable attacker could create and execute flows without authentication. Default script plugins can convert that access into command execution as root inside the worker container. Container root is not automatically host root; Kestra's advisory says its testing did not confirm a direct Docker-socket escape.
The advisory identifies affected releases through 1.3.20 and names patched releases 1.0.45 and 1.3.21. Because those are branch-specific fixes rather than a safe single numeric comparison, use the patched release applicable to the installed line, or a later supported release. Exposure does not require public internet access: any attacker who can reach the service on the relevant network path can attempt it. Microsoft assessed with high confidence that initial access to an observed compromised Kestra workload likely involved CVE-2026-49869; the observed post-compromise activity included a reverse shell, container and Docker-environment discovery, cryptocurrency mining, and data collection.
Starlette. CVE-2026-48710, CVSS 3.1 score 6.5, allows a crafted Host header to make request.url.path differ from the path actually routed by the application. Applications that make authorization decisions from the reconstructed URL can therefore be bypassed. Starlette 1.0.0 and earlier are affected; 1.0.1 fixes the issue. A reverse proxy is a mitigation only if it reliably rejects or normalizes malformed host data and does not reintroduce attacker-controlled forwarded-host values.
LiteLLM. CVE-2026-59822, CVSS v4 score 8.8, allowed an arbitrary Bearer token to establish an MCP Streamable HTTP session. An unauthenticated attacker could list and call configured MCP tools and reach connected services with the gateway's delegated authority. Versions earlier than 1.84.0 are affected; 1.84.0 fixes the flaw. If immediate upgrade is impossible, block or disable /mcp/ and related MCP routes until the fix is deployed. Wiz says its honeypots observed attempts using a single-character token to enumerate models, which supports active probing but is not a production-victim count.
Starlette CVE-2026-48710 can make another application's path-based protection ineffective. Microsoft assessed with high confidence that initial access to one observed LiteLLM workload was likely consistent with a chain involving the Starlette flaw and LiteLLM command-injection CVE-2026-42271. “Likely” is important: the telemetry did not prove the exact exploit chain. The September 2 catalog action covers Starlette CVE-2026-48710 and LiteLLM CVE-2026-59822; it should not be misread as proof that every Starlette application or every LiteLLM deployment was exploited.
Operational consequence. AI and workflow gateways combine network reachability, high-value secrets, tool permissions, model access, and automation. Application-level command execution or tool authorization bypass can quickly become cloud, data, or software-delivery compromise.
Evidence: GitHub Security Advisories maintained by the affected projects; catalog action reported by The Hacker News; Microsoft incident telemetry and confidence-qualified assessment; Wiz honeypot observations.
Attribution: no common actor is established. Microsoft explicitly described distinct compromised workloads, not one confirmed campaign.
Confidence: high for affected/fixed versions and vulnerability mechanics; high that exploitation activity exists; moderate for the precise initial-access chain in Microsoft's LiteLLM case.
Uncertainty: the number of production victims, the identities of operators, lateral movement, and the extent of secret or connected-service access remain unknown.
Sources: Kestra GitHub Security Advisory GHSA-5vc5-wxxq-3fjx (accessed September 3, 2026); Starlette GitHub Security Advisory GHSA-86qp-5c8j-p5mr (accessed September 3, 2026); LiteLLM GitHub Security Advisory GHSA-7488-6r32-c95q (accessed September 3, 2026); Microsoft Security Blog, “When AI infrastructure becomes a target: Securing gateways and control points” (August 26, 2026); Wiz, “AI Infrastructure Honeypot” (accessed September 3, 2026); The Hacker News KEV report (September 3, 2026); CVE Program records for CVE-2026-49869, CVE-2026-48710, and CVE-2026-59822.
RED — Global | Hosting and virtualization | Provider account adds confirmed root compromises to the Virtualizor incident
What changed. Virtualizor had already disclosed that a Border Gateway Protocol route hijack redirected update and client-billing traffic for 162.55.80.0/24 from August 28 at 20:57 UTC until August 30 at 06:10 UTC. New reporting published after the previous briefing's cutoff attributes a concrete estate-level result to hosting provider AlbaHost: five of 34 hypervisor nodes it checked were compromised. This is one provider's report, not an ecosystem prevalence rate.
Virtualizor says the unauthorized route was originated by AS62390 and propagated through AS6204. Route control allowed the hostile server to satisfy domain validation and obtain a valid Let's Encrypt certificate. A malicious Virtualizor package was then delivered to a small number of systems. The vendor cannot enumerate every recipient because update traffic reached infrastructure controlled by the attacker.
AlbaHost reported a root SSH key, a Java payload persisted through /etc/systemd/system/java-jre-update.service, an unauthorized proxyuser, and an SSH login from 193.32.127[.]248. Its report found no evidence that guest virtual machines were compromised, but absence of observed guest activity is not proof of guest integrity when the hypervisor host had root-level persistence.
Virtualizor 3.2.9.9, released September 1, adds mitigation and a security analyzer. The vendor also says cryptographic package signing is future work. Operators should therefore validate node integrity independently: preserve disk, memory, network, shell, and update evidence; isolate positives; audit users, root and authorized SSH keys, systemd units, cron, outbound traffic, API keys, and billing access; scope management peers and backups; and rebuild from trusted media if root integrity cannot be demonstrated. Rotate or restrict Virtualizor API keys and credentials reachable from the panel. Users who authenticated to the client portal during the hijack window should rotate exposed credentials.
Operational consequence. The event converted routing control into software-update trust. A compromised virtualization host can expose tenant workloads, storage, backups, management credentials, and east-west control paths even when guest compromise has not been observed.
Evidence: Virtualizor's incident statement and indicators; RIPE routing visualization; a named provider's self-reported investigation, relayed with concrete host artifacts by The Hacker News.
Attribution: unknown. Autonomous-system and IP observations describe infrastructure behavior, not the responsible person or group.
Confidence: high for the routing interval, update-delivery mechanism, and vendor indicator; moderate-to-high for AlbaHost's five-node finding because it is specific but provider-reported rather than independently imaged.
Uncertainty: total recipients, additional persistence, stolen data, tenant impact, and whether other provider environments were compromised remain unknown.
Sources: Virtualizor, “Security Incident — BGP Hijacking” (updated September 1, 2026); The Hacker News, “BGP Hijack Delivers Malicious Virtualizor Update” (September 3, 2026); RIPEstat BGPlay for 162.55.80.0/24 (accessed September 3, 2026).
RED — Germany | Electricity | Generation restoration advances while the sabotage investigation broadens
What changed. Three of the five lignite-fired generating units tripped in the Bergheim, North Rhine-Westphalia incident have returned to service. Grid operator Amprion expected the remaining two during the weekend and said there was no blackout risk. In Brandenburg, the search around Jänschwalde ended at midday September 3 and the L50 road reopened, while the state criminal police investigation continued under offenses that include suspected formation of a terrorist organization.
The legal basis of an investigation is not a conclusion that a terrorist organization exists or carried out the incidents. Brandenburg's interior minister said indications of a coordinated connection with North Rhine-Westphalia were increasing; a connection remains unproven. The federal prosecutor was considering whether to assume the case, and domestic intelligence was involved. No responsible actor has been identified publicly.
The operational facts remain material. Near Bergheim, investigators found six launch devices in a cornfield after projectiles caused five RWE units to trip; approximately 3,000 MW was being generated at the time against 4,200 MW of nameplate capacity. Near Jänschwalde, devices launched conductive material toward extra-high-voltage lines, caused short circuits, and led one power-station unit to shut down. General electricity supply remained stable in both cases.
Restoration demonstrates reserve and recovery capacity, but it does not close the security problem. Operators should maintain physical patrols, line and substation inspection, camera and access-log preservation, coordination with agricultural and land owners near rights of way, monitoring for staged launch mechanisms, and cyber review of protection and control systems only where evidence supports a digital path. Nothing reviewed by the cutoff establishes a cyber component.
Operational consequence. Low-cost, remotely or mechanically delivered conductive and incendiary devices can create generation trips and investigative burdens without breaching a fenced control room. Repetition across regions could erode reserve margins even when one event does not interrupt public supply.
Evidence: police and grid-operator statements reported by German public broadcasters; earlier incident detail corroborated by Reuters and the Associated Press.
Attribution: unknown. A cross-state link is an investigative hypothesis, not an established fact.
Confidence: high for the incidents, unit trips, restoration count, and lack of public-supply interruption; low for common authorship or motive.
Uncertainty: device authorship, coordination, target selection, remaining devices, and whether a broader campaign exists remain unresolved.
Sources: Deutschlandfunk, “Drei Kraftwerksblöcke in Bergheim wieder am Netz” (September 3, 2026); rbb24, “Sabotage an Stromnetz: Ermittlungen wegen Terrorverdachts” (updated September 3, 2026); Reuters reports on the Brandenburg and North Rhine-Westphalia incidents (September 1–2, 2026); Associated Press, report on suspected sabotage against German power infrastructure (September 2, 2026).
AMBER — Global, with government concentration | Geospatial services | Two GeoNetwork flaws form a pre-authentication RCE chain
What changed. Ethiack published a working chain against GeoNetwork 4.4.11 using two flaws now fixed by the project. CVE-2026-63219, CVSS 8.6, permits an unauthenticated user to upload formatter .xsl or .zip content. CVE-2026-58400, CVSS 9.1, allows a privileged formatter upload to invoke unsafe Saxon Java functions and execute code as the GeoNetwork process. Chaining the authorization failure with unsafe transformation behavior produces pre-authentication remote code execution.
GeoNetwork 4.4.11 and earlier on the 4.4 line and 4.2.16 and earlier on the 4.2 line are affected according to the project advisories. Fixed releases are 4.4.12 and 4.2.17. If patching cannot be completed immediately, block unauthenticated POST, PUT, and PATCH requests to the exact formatter API path /geonetwork/srv/api/formatters; a broad or approximate proxy rule should not be assumed equivalent.
Ethiack identified 121 internet-reachable 4.x deployments in 39 countries that it assessed as affected; 89% of its sample belonged to government, military, or national-agency organizations, and 77.7% were in Europe or the European Union. These figures describe a researcher's exposure sample, not confirmed exploitation or victims. No malicious exploitation was confirmed in the reviewed primary sources, and neither flaw was in the KEV action reviewed for this briefing.
Review existing formatters, application and reverse-proxy logs, recent archive or XSL uploads, unexpected Java child processes, outbound connections, and the integrity of geospatial metadata. Compromise could alter or suppress data relied on for emergency management, land use, defense, logistics, or public information even if the service remains online.
Evidence: two project-maintained GitHub Security Advisories and a reproducible research chain; researcher internet-exposure measurement.
Attribution: none; this is vulnerability research, not an attributed intrusion.
Confidence: high for the chain and fixed versions; moderate for the external exposure estimate; no basis to claim in-the-wild exploitation.
Uncertainty: the number of still-unpatched instances, private-network exposure, exploitation before disclosure, and the integrity of individual catalogs are unknown.
Sources: GeoNetwork GitHub Security Advisory GHSA-mh22-prqr-vf42 (accessed September 3, 2026); GeoNetwork GitHub Security Advisory GHSA-x898-729x-cc3r (accessed September 3, 2026); Ethiack, “GeoNetwork Pre-Auth RCE” (accessed September 3, 2026); CVE Program records for CVE-2026-63219 and CVE-2026-58400.
AMBER — United States and Canada | Justice systems | C-Track files were taken months before detection
What changed. Thomson Reuters' C-Track disclosed that it detected unauthorized third-party activity in its cloud environment on June 30 and later determined that certain files had been obtained in March. The U.S. notice identifies court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Ohio, Wyoming, and the U.S. Virgin Islands. Ontario separately says C-Track notified three of its courts.
The potentially affected material varies by court and person. A subset of court records may contain names, Social Security numbers, driver's-license numbers, dates of birth, medical information, or health-insurance information; confidential, redacted, or sealed material may also be involved. This does not mean every listed jurisdiction or record contained every data type.
C-Track and court notices say the platform remained operational and safe to use, no financial-transaction system was affected, and no fraud or misuse had been identified at the time of notice. Those statements reduce evidence of an availability event; they do not eliminate confidentiality, identity, safety, or legal-process risk.
There is a source discrepancy. North Dakota's republication names Oregon in addition to the jurisdictions above, while C-Track's dedicated U.S. notice and Reuters describe 11 states. This briefing follows the current dedicated C-Track notice and preserves the discrepancy as unresolved rather than converting it into a twelfth confirmed state.
Courts should obtain a tenant-level inventory of accessed files and timestamps, preserve administrative and access logs, validate containment and credential rotation, trace exports and integrations, review access to sealed or redacted matters, and tailor notice to the data actually affected. Security teams should anticipate phishing that impersonates courts, law firms, litigants, or identity-monitoring providers.
Operational consequence. Court data can expose protected identities, medical circumstances, legal strategy, law-enforcement material, and sealed proceedings. Even without downtime, confidentiality loss can create personal-safety, due-process, fraud, and public-trust consequences.
Evidence: C-Track's dedicated U.S. and Canadian notices; Ontario and North Dakota court notices; Thomson Reuters statements reported by Reuters.
Attribution: unknown. No actor, access vector, or motive had been publicly established by the cutoff.
Confidence: high that files were obtained and that the platform remained operational; moderate for jurisdiction scope because the notices conflict; low for affected-person count and downstream use.
Uncertainty: file inventory, number of people, exact courts and cases, dwell time, initial access, exfiltration volume, and misuse remain unresolved.
Sources: C-Track, “Notice of Data Event — United States” (September 2, 2026); C-Track, “Notice of Data Event — Canada” (September 2, 2026); Ontario Courts, “Public Statement: Cybersecurity” (accessed September 3, 2026); North Dakota Courts, “C-Track Data Incident” (accessed September 3, 2026); Reuters, “Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files” (September 3, 2026).
Defensive Posture Changes
1. Treat newly listed control-plane flaws as incident-response triggers
For an internet-reachable or otherwise attacker-reachable affected system, create one record that joins asset identity, exact version, exposure path, authentication configuration, patch status, and evidence review. A successful patch does not erase pre-patch access. Retain and inspect logs before normal rotation or retention destroys them.
2. Make AI gateways a dedicated trust zone
Inventory every model gateway, MCP endpoint, workflow engine, tool connector, secret store, and service identity. Alert on unauthenticated MCP negotiation, model or tool enumeration, unexpected workflow creation, application-spawned shells, reads of /proc/1/environ, Docker-socket discovery, miner activity, and outbound connections not required by the service. After suspected access, rotate the credentials the process could read—not just the application's local password.
3. Verify software-delivery trust out of band
The Virtualizor case shows that TLS alone does not authenticate a supplier when route control lets an adversary complete certificate validation. Require signed packages and verified metadata where available; monitor route origin and RPKI state; pin or independently verify update identity for critical management software; and maintain a trusted offline rebuild path. Virtualizor says package signing remains future work, so compensating validation is still necessary.
4. Fuse physical-security and operations telemetry
German incidents show why power output, relay events, line faults, camera records, access logs, fire detections, and local observations should be correlated on one timeline. Keep cyber hypotheses available, but do not force a cyber explanation onto evidence that currently supports physical interference.
5. Demand record-level supplier-breach provenance
For C-Track, a generic “affected customer” label is insufficient. Courts need file names or data classes, access timestamps, tenant identifiers, relevant identities, logging limits, containment dates, and downstream subprocessor facts. Use those facts to decide notice, protective orders, identity monitoring, and case-specific safety measures.
Regional and Sector Pulse
- Europe — RED: German generation capacity is returning, but repeated line-interference methods and unresolved common authorship justify elevated physical-security posture. GeoNetwork exposure is disproportionately concentrated in the researcher's European-government sample.
- North America — AMBER: C-Track's disclosure creates a cross-jurisdiction confidentiality and supplier-risk problem without a reported court-service outage. The exact state count remains subject to a documented notice discrepancy.
- Global technology and hosting — RED: exploited flaws cluster in remote access, telephony, artifact repositories, AI gateways, and workflow engines. The Virtualizor update incident adds a separate route-to-software-supply-chain path with provider-reported root compromise.
- Industrial operations — AMBER: Rockwell controller and historian flaws warrant planned firmware action. Current reviewed evidence does not establish exploitation.
- Other regions — WATCH: no additional region-specific development reviewed by the cutoff met the threshold for a new ledger entry. Global exposure to the affected technology stacks still applies.
Vulnerability and Supplier Watchlist
- SonicWall SMA1000 — CVE-2026-83548 / CVE-2026-83549: vendor scores 10.0 and 7.8, respectively; models 6210, 7210, and 8200v; affected
12.4.3-03453and earlier or12.5.0-02835and earlier; fixed12.4.3-03526and12.5.0-02952; RED, exploited/KEV. - Sangoma Switchvox — CVE-2026-9586: CVSS v4 9.3; unauthenticated SQL injection to OS command execution; reproduced on SMB Edition
8.3build104997; fixed8.4.0.2or later; RED, exploited/KEV. - JFrog Artifactory — CVE-2026-82329: CVSS 9.8; self-hosted default-configuration authentication failure; fixed branch releases
7.111.21,7.117.28,7.125.20,7.133.29,7.146.38,7.161.20; JFrog Cloud already fortified; RED, exploited/KEV. - Kestra — CVE-2026-49869: CVSS 10.0; unauthenticated flow creation and execution in the affected OSS default basic-auth configuration; fixed
1.0.45and1.3.21on the applicable branches; RED, exploited/KEV. - Starlette — CVE-2026-48710: CVSS 3.1 score 6.5; host-header path inconsistency affecting
1.0.0and earlier; fixed1.0.1; RED when used for path-based authorization, exploited/KEV. - LiteLLM — CVE-2026-59822: CVSS v4 8.8; MCP authentication bypass affecting versions earlier than
1.84.0; fixed1.84.0; RED, exploited/KEV. - GeoNetwork — CVE-2026-63219 / CVE-2026-58400: advisory scores 8.6 and 9.1, respectively; unauthorized formatter upload plus unsafe XSLT execution; affected
4.4.11and earlier or4.2.16and earlier; fixed4.4.12and4.2.17; AMBER, no confirmed malicious exploitation. - Rockwell ControlLogix/CompactLogix/GuardLogix families — CVE-2026-9637: malformed CIP input can cause a major nonrecoverable fault requiring a power cycle. Affected Version 33 and earlier,
34.011–34.014,35.011–35.013, and36.011–36.012; fixed34.015,35.014,36.013, and37.011; WATCH. Rockwell's page header says “KEV: Yes,” while its detailed CVE row says “Known Exploited Vulnerability: No.” Without corroboration, this briefing treats exploitation as unconfirmed. - Rockwell FactoryTalk Historian ME 1756-HIST2G Series B/C — CVE-2025-12768 / CVE-2026-12661: CVSS 3.1 scores 8.0 and 4.5, and CVSS v4 scores 8.6 and 4.8, respectively; authenticated code execution and adjacent authenticated web-service crash conditions; affected Series B
5.202and Series C7.101; fixed Series B5.203and Series C7.102; WATCH, no known exploitation in the vendor advisory. - C-Track court case-management cloud: file-access incident detected June 30, with files obtained in March; no CVE or customer-deployed fixed version applies; AMBER, supplier incident. Require court-specific scope and containment evidence.
Outlook and Uncertainty
Next 24 hours
- Expect accelerated scanning and exploitation attempts against the five products facing the September 5 federal deadline, including copycat activity that may not share an actor.
- Watch for vendor or responder publication of additional indicators for SMA1000, Artifactory, Switchvox, and the AI control-plane flaws.
- Expect further Virtualizor provider scoping. A new validated compromise count, signed-package change, or guest-impact finding would materially change the assessment.
- German restoration should continue, but discovery of additional launch devices, a confirmed forensic link between states, or federal assumption of the case would raise confidence in a coordinated campaign.
- C-Track's affected-court and person counts may change as tenant-level review proceeds. The Oregon discrepancy should be resolved against the vendor's current authoritative list.
What remains unknown
- Whether the seven newly listed vulnerabilities were exploited by one or many actors, and the number of production victims.
- Whether compromised Artifactory instances were used to modify artifacts or reach downstream build systems.
- Whether AI gateway access exposed model data, cloud credentials, MCP-connected services, or Docker control paths.
- How many Virtualizor systems received the malicious package and whether any guest, backup, or orchestration layer was accessed.
- Whether the German incidents share authorship, motive, supply chain, or command structure.
- Which C-Track files and people were affected, and whether March access persisted beyond the known collection period.
- Whether GeoNetwork exploitation occurred before public disclosure.
Escalation triggers
- A vendor-confirmed additional victim set, persistence mechanism, stolen-data set, or destructive action tied to a listed product.
- Evidence of artifact tampering, signing-key access, or downstream deployment from a compromised Artifactory instance.
- Verified host escape, cloud-control-plane access, or connected-service abuse from an AI or workflow compromise.
- Additional Virtualizor hypervisor root compromises, guest impact, or a repeated routing-to-update operation against another vendor.
- Confirmed common forensic markers or an attributable claim linking the German electricity incidents.
- C-Track confirmation that sealed records, protected witnesses, law-enforcement data, or high-risk individuals were exposed.
- Credible in-the-wild exploitation of either GeoNetwork CVE.
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Source Register
September 3, 2026
Reporting cutoff: September 3, 2026, 14:10 UTC
This register preserves full, spelled-out URLs by story. The briefing intentionally does not link to CISA.gov or the CISA Known Exploited Vulnerabilities catalog because those destinations do not forward reliably from bordercybergroup.com. The September 2 catalog action is therefore sourced through a dated independent news report, while vulnerability mechanics and fixed versions are sourced to vendors, project advisories, and CVE records.
1. September 2 Known Exploited Vulnerabilities action
Independent report used for the seven additions and federal deadlines:
https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html
2. SonicWall SMA1000 — CVE-2026-83548 and CVE-2026-83549
SonicWall Product Security Incident Response Team advisory:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Independent reporting:
https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/
CVE records:
https://www.cve.org/CVERecord?id=CVE-2026-83548
https://www.cve.org/CVERecord?id=CVE-2026-83549
3. Sangoma Switchvox — CVE-2026-9586
Horizon3.ai technical disclosure and exploitation telemetry:
https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
Sangoma fixed-release notes:
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-9586
4. JFrog Artifactory — CVE-2026-82329
JFrog security advisories:
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Independent reporting with attributed watchTowr observations:
https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html
CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-82329
5. AI and workflow control planes — Kestra, Starlette, and LiteLLM
Kestra GitHub Security Advisory for CVE-2026-49869:
https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx
Starlette GitHub Security Advisory for CVE-2026-48710:
https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
LiteLLM GitHub Security Advisory for CVE-2026-59822:
https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q
Microsoft incident observations and confidence-qualified access assessments:
Wiz honeypot observations:
https://www.wiz.io/blog/ai-infrastructure-honeypot
CVE records:
https://www.cve.org/CVERecord?id=CVE-2026-49869
https://www.cve.org/CVERecord?id=CVE-2026-48710
https://www.cve.org/CVERecord?id=CVE-2026-59822
LiteLLM command-injection CVE referenced in Microsoft's assessed Starlette-to-LiteLLM chain:
https://www.cve.org/CVERecord?id=CVE-2026-42271
6. Virtualizor BGP hijack and malicious update
Virtualizor incident statement:
https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
Independent report carrying AlbaHost's estate findings:
https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html
Additional independent reporting:
RIPEstat BGPlay route history for 162.55.80.0/24:
https://stat.ripe.net/bgplay/162.55.80.0%2F24
7. German electricity-infrastructure incidents
Bergheim restoration update:
https://www.deutschlandfunk.de/drei-kraftwerksbloecke-in-bergheim-wieder-am-netz-100.html
Brandenburg investigation update:
Reuters reporting on the Brandenburg incident:
Reuters reporting on the North Rhine-Westphalia incident:
Associated Press corroboration:
https://apnews.com/article/ef9c21908f232651d056d7462330e2b7
8. C-Track court-platform data incident
C-Track United States notice:
https://www.ctracknotification.com/
C-Track Canada notice:
https://www.ctracknotification.ca/en
Ontario Courts statement:
https://www.ontariocourts.ca/en/public-statement-cybersecurity.htm
North Dakota Courts republication, retained to document the Oregon jurisdiction discrepancy:
https://www.ndcourts.gov/supreme-court/c-track-data-incident
Reuters reporting:
9. GeoNetwork pre-authentication RCE chain — CVE-2026-63219 and CVE-2026-58400
GeoNetwork project advisory for the unauthorized formatter upload:
https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-mh22-prqr-vf42
GeoNetwork project advisory for unsafe XSLT execution:
https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-x898-729x-cc3r
Ethiack research and exposure sample:
https://ethiack.com/info-hub/research/geonetwork-preauth-RCE
Independent reporting:
https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
CVE records:
https://www.cve.org/CVERecord?id=CVE-2026-63219
https://www.cve.org/CVERecord?id=CVE-2026-58400
10. Rockwell Automation OT watchlist
Rockwell advisory for CVE-2026-9637, including the internally conflicting KEV fields noted in the briefing:
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1792.html
Rockwell advisory for CVE-2025-12768 and CVE-2026-12661:
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1796.html
Member discussion: