Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091411094040 | Publication Time | 2026-09-14 11:48:41 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 11:48:41 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA Added 10 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/31-2026/09/06) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000009 【CVE-2026-82078】PaperCut NG/MF Unsafe Reflection Vulnerability (CVSS v3.1: 9.1) 【CVE-2026-81578】PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-59822】BerriAI LiteLLM Improper Authentication Vulnerability (CVSS v3.1: 8.2) 【CVE-2026-48710】Kludex Starlette HTTP Request/Response Smuggling Vulnerability (CVSS v3.1: 6.5) 【CVE-2026-49869】Kestra OSS OS Command Injection Vulnerability (CVSS v3.1: 10.0) 【CVE-2026-82329】JFrog Artifactory Improper Authentication Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-9586】Sangoma Switchvox SQL Injection Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-83548】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0) 【CVE-2026-83549】SonicWall SMA1000 Appliances OS Command Injection Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-85046】Google Chromium V8 Type Confusion Vulnerability (CVSS v3.1: 8.8) Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
【CVE-2026-82078】Please refer to the affected versions listed by the official vendor: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 【CVE-2026-81578】Please refer to the affected versions listed by the official vendor: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 【CVE-2026-59822】Please refer to the affected versions listed by the official vendor: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q 【CVE-2026-48710】Please refer to the affected versions listed by the official vendor: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr 【CVE-2026-49869】Please refer to the affected versions listed by the official vendor: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx 【CVE-2026-82329】Please refer to the affected versions listed by the official vendor: https://docs.jfrog.com/releases/docs/jfrog-security-advisories 【CVE-2026-9586】Please refer to the affected versions listed by the official vendor: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 【CVE-2026-83548】Please refer to the affected versions listed by the official vendor: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 【CVE-2026-83549】Please refer to the affected versions listed by the official vendor: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 【CVE-2026-85046】Please refer to the affected versions listed by the official vendor: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
|
|||
|
[Recommended Actions] 【CVE-2026-82078】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 【CVE-2026-81578】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ 【CVE-2026-59822】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q 【CVE-2026-48710】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr 【CVE-2026-49869】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx 【CVE-2026-82329】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://docs.jfrog.com/releases/docs/jfrog-security-advisories 【CVE-2026-9586】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 【CVE-2026-83548】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 【CVE-2026-83549】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 【CVE-2026-85046】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html |
|||
|
[Reference] |
|||