The trailing ~48 hours (August 31 – September 1, 2026) were dominated by software supply chain compromise. Every item below was checked against a primary vendor advisory, CISA KEV entry, or the original research report, and confirmed to fall inside the window.
Attackers mint admin tokens on JFrog Artifactory days after disclosure (CVE-2026-82329)
watchTowr · September 1, 2026
CVE-2026-82329 (CVSS 9.8) is an authentication bypass in JFrog Access, the component that issues and validates Artifactory credentials. Under default configuration, an unauthenticated attacker with network access can obtain administrative privileges — instances without an additional join key configured receive a “phantom” join key that can be abused to forge access and mint administrator-level credentials. JFrog patched the flaw in Artifactory 7.161.20 on August 28, 2026; affected branches include 7.161.0–7.161.19, 7.146.0–7.146.36, 7.133.0–7.133.28, 7.125.0–7.125.19, 7.117.0–7.117.27, and 7.111.4–7.111.21. watchTowr reported that threat actors began weaponizing the flaw on September 1, generating admin tokens and enumerating users, groups, credential sets, and federated access topologies. The CVE is not in the CISA KEV catalog as of this writing.
“This moved from disclosure to real-world exploitation with uncomfortable efficiency.”
— Yordan Ganchev, principal threat intelligence specialist, watchTowr
Source: CVE-2026-82329 (CVE.org) · JFrog security advisories · The Hacker News
BGP hijack redirected Virtualizor update traffic, delivering a malicious package
Softaculous · September 1, 2026
Softaculous disclosed that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker announced a false route for a block of Hetzner-hosted IP addresses, diverting traffic destined for its software update systems and client/billing portal. The hijack allowed a malicious Virtualizor update package to reach a small number of hosting-provider installations that happened to check for updates during the window. Because requests never reached Softaculous, the vendor has no logs of who was served the package. There is no CVE — this is an infrastructure-level supply chain compromise, not a product vulnerability. Operators are told to check for the service file /etc/systemd/system/java-jre-update.service, rotate and restrict API credentials, and audit for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Routing has been restored, the fraudulent certificate was reported for revocation, and Virtualizor 3.2.9.9 shipped September 1 with a Security Analyzer tool. Softaculous says it will add cryptographic signing for all packages going forward.
“We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted.”
— Softaculous security incident notice
Source: Virtualizor security incident notice · BleepingComputer
CISA adds the exploited PaperCut NG/MF chain to KEV with a September 14 deadline
CISA · August 31, 2026
CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on August 31, setting a September 14, 2026 remediation deadline for federal civilian agencies. CVE-2026-81578 (CVSS 8.8) is an improper access control flaw in the PaperCut NG/MF web management interface; CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class-loading flaw in the product’s database connection utilities. Chained, they yield pre-authentication remote code execution. The bugs were exploited as zero-days before a fix existed, and PaperCut shipped Emergency Patch Release 2 on August 28 after watchTowr and Huntress found multiple bypasses of the first patch — customers who applied the original emergency patch still need Release 2. Patches cover NG/MF versions 24, 25, and 26 on Windows, Linux, and macOS; version 23 and earlier require an upgrade.
“Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks.”
— PaperCut security bulletin, 27 Aug 2026
Source: CISA KEV alert · PaperCut security bulletin · BleepingComputer
VulnCheck canaries log credential harvesting against Langflow and Rails
VulnCheck · September 1, 2026
VulnCheck reported active exploitation of two critical flaws. CVE-2026-0768 (CVSS 9.8) is an input-validation failure in the code validator behind Langflow’s custom component editor that allows unauthenticated arbitrary Python execution as root. CVE-2026-66066, “KindaRails2Shell” (CVSS 9.5), is an Active Storage/libvips arbitrary file read in Ruby on Rails that leaks secret_key_base, master keys, database passwords, and cloud credentials, and can escalate to RCE. VulnCheck recorded more than 50 detections in a few hours on August 30, rising to 360 by September 1. Both CVEs are patched upstream, though VulnCheck noted that on a patched Rails 8.1.3.1 server the fix blocks the libvips file read but does not neutralize the variation-key Marshal deserialization gadget. Neither CVE appears in KEV as of this writing.
“Source traffic primarily originates from Russia and has thus far exclusively hit Canaries in the U.K.”
— Caitlin Condon, vice president of threat research, VulnCheck
Source: ZDI-26-034 (CVE-2026-0768) · VulnCheck initial access report · The Hacker News
This brief covers the trailing ~48 hours (August 31 – September 1, 2026).
Primary sources:
- CVE-2026-82329 — CVE.org
- JFrog Security Advisories
- Virtualizor — Security Incident: BGP Hijacking
- CISA — Adds Two Known Exploited Vulnerabilities to Catalog (Aug 31, 2026)
- PaperCut — Urgent Security Advisory (27 Aug 2026)
- Zero Day Initiative — ZDI-26-034
- VulnCheck — Initial Access Intelligence: CVE-2026-66066