VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR flags actively exploited SonicWall, Mikrotik, JFrog bugs

severe vulnerability technologyinfrastructuretelecommunications

France's CERT-FR weekly bulletin highlights actively exploited critical flaws in SonicWall SMA, Mikrotik RouterOS, JFrog Artifactory and several other widely deployed products.

CERT-FR's weekly vulnerability roundup for week 36 (31 Aug–6 Sep 2026) lists over 20 high/critical CVSS vulnerabilities across major vendors including Google Chrome, Microsoft Edge, Cisco NX-OS/IOS XR, HPE Aruba Networking, Mozilla, and Tenable. Most notably, several vulnerabilities are confirmed as actively exploited in the wild: a JFrog Artifactory authentication bypass leading to admin access (CVE-2026-82329, CVSS 9.8), and — most urgently — two SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities (CVE-2026-83548, an unauthenticated SSRF, and CVE-2026-83549, authenticated RCE) that SonicWall confirms are under active exploitation. SonicWall's guidance goes beyond patching, recommending full system reinstallation, password resets, and TOTP token resets for affected appliances, indicating high confidence of full-device compromise in observed incidents.

Separately, CERT-PL reported active SSH-based exploitation of multiple MikroTik RouterOS vulnerabilities, with compromise indicators published. Other actively exploited vulnerabilities named in the bulletin include Kestra (CVE-2026-49869, CVSS 10 RCE), Langflow (CVE-2026-0768), Sangoma Switchvox (CVE-2026-9586, RCE/SQLi), LiteLLM (CVE-2026-59822), and Starlette (CVE-2026-48710), plus a PostgreSQL flaw (CVE-2026-6471) with public exploit code available. A long list of additional critical-severity vulnerabilities (Chrome, Edge, Aruba Fabric Composer/AOS-CX, Cisco NX-OS/IOS XR) were disclosed with no confirmed in-the-wild exploitation at time of publication but warrant prompt patching given their severity and prevalence in enterprise/network infrastructure.

Defenders operating SonicWall SMA 1000, MikroTik RouterOS, JFrog Artifactory, Kestra, Langflow, Sangoma Switchvox, LiteLLM, or Starlette should treat these as priority patches and check for the published compromise indicators (obtainable via SonicWall support and CERT-PL's advisory) rather than relying on patching alone, given evidence of post-exploitation persistence.

Mentioned in this report

Vulnerabilities CVE-2026-0768templatedCVE-2026-19626weaponizedCVE-2026-19766CVE-2026-20212CVE-2026-20274CVE-2026-20279CVE-2026-48710KEVCVE-2026-49869KEVCVE-2026-59822KEVCVE-2026-6471CVE-2026-73700CVE-2026-73701CVE-2026-73749CVE-2026-76657CVE-2026-76658CVE-2026-79090CVE-2026-82329KEVCVE-2026-83548KEVCVE-2026-83549KEVCVE-2026-84137CVE-2026-84333CVE-2026-84352CVE-2026-84353CVE-2026-84354CVE-2026-85042CVE-2026-85046KEVCVE-2026-85047CVE-2026-85050CVE-2026-9586KEV

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-038

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free