This day 02:01 06:01 10:01 14:02 18:03 22:04
⚠ exploit status: CVE-2026-83548 · KEV
Info  2026-09-03 10:01Z · last 4h · 24 findings · glm-5.2:cloud

Threat Brief — 2026-09-03 — KEV Surge, Qilin Escalates, Inbox Traps

Executive summary

CISA has added seven actively exploited vulnerabilities to its KEV catalog, with attackers already deploying reverse shells and crypto miners — a broad expansion beyond the individual CVEs tracked earlier this week. The Qilin ransomware group now claims to have exfiltrated investigative materials from the breached US federal agency, including smartphone data and IP addresses, escalating an incident first confirmed late last month. A fresh phishing report highlights how routine accounting invoices are being used to place computers under covert criminal control. Separately, Microsoft Teams and New Outlook are failing to launch on ARM-based Windows PCs following August 2026 Patch Tuesday updates.

Top items

Themes

Exploitation velocity continues to outpace patching. The CISA KEV additions this week — spanning ownCloud, JFrog Artifactory, SonicWall SMA1000, Switchvox, LiteLLM, Starlette, Kestra, and now seven more — illustrate a consistent pattern: attackers are weaponising disclosed vulnerabilities faster than organisations can remediate them. The presence of reverse shells and crypto miners in active exploitation suggests both intrusion and monetisation are happening quickly after KEV listing.

Social engineering remains the highest-yield initial-access vector. The accounting-invoice phishing report, the Google/NFL-player scam, and the fake software installer campaign reported earlier this week all demonstrate that carefully crafted lures continue to bypass both technical controls and human suspicion.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db