Daily Cybersecurity flagged nine actively exploited vulnerabilities before or beyond CISA this week. That is the standout finding from the latest CVE WATCHTOWER report, spanning August 31 to September 6, 2026. The tracker also logged 2,316 new CVEs over the same period. This weekly CVE report puts the two feeds side by side, so you can measure the intelligence lead time in days.
The week in numbers
Volume set the backdrop this week. CVE WATCHTOWER recorded 2,316 fresh disclosures across the seven-day window. Of those, 271 rated critical, and another 708 landed as high severity. So roughly a thousand new flaws demand near-term attention.
Yet counts alone do not equal risk. Confirmed exploitation does. Daily Cybersecurity’s intelligence sources marked nine flaws as ACTIVE this week. Five of them reached CISA’s Known Exploited Vulnerabilities (KEV) catalog a day later. The other four never made the KEV catalog at all.
The intelligence lead: Daily Cybersecurity vs CISA KEV
The table below compares when Daily Cybersecurity marked each flaw exploited against the official CISA KEV “date added.” The lead-time column shows the gap. Four flaws remain exclusive to Daily Cybersecurity, since CISA has not listed them.
| CVE ID | Affected product | DC marked exploited | CISA KEV date added | Lead time |
|---|---|---|---|---|
| CVE-2026-82329 | JFrog Artifactory | 2026-09-01 | 2026-09-02 | 1 day earlier |
| CVE-2026-9586 | Sangoma Switchvox SMB | 2026-09-01 | 2026-09-02 | 1 day earlier |
| CVE-2026-83548 | SonicWall SMA1000 (Work Place) | 2026-09-01 | 2026-09-02 | 1 day earlier |
| CVE-2026-83549 | SonicWall SMA1000 (AMC) | 2026-09-01 | 2026-09-02 | 1 day earlier |
| CVE-2026-85046 | Google Chrome (V8) | 2026-09-03 | 2026-09-04 | 1 day earlier |
| CVE-2026-0768 | Langflow | 2026-09-01 | Not listed | Exclusive to DC |
| CVE-2026-35029 | LiteLLM (AI Gateway) | 2026-09-01 | Not listed | Exclusive to DC |
| CVE-2026-32475 | Elementor Pro (WordPress) | 2026-09-02 | Not listed | Exclusive to DC |
| CVE-2026-14894 | Super Forms (WordPress) | 2026-09-04 | Not listed | Exclusive to DC |
The pattern is clear. On every flaw the two feeds share, Daily Cybersecurity flagged the exploitation a full day ahead. More striking, four critical bugs surfaced only through Daily Cybersecurity. A team waiting on CISA KEV alone would have missed those entirely.
Exploited vulnerabilities from CISA KEV only
These five exploited vulnerabilities appear on CISA KEV but not in Daily Cybersecurity’s ACTIVE feed this week. Each still warrants urgent patching. The “CISA KEV date added” column reflects the official catalog.
| CVE ID | Affected product | Vulnerability type | CVSS | CISA KEV date added |
|---|---|---|---|---|
| CVE-2026-82078 | PaperCut NG/MF | Unsafe dynamic class loading | 9.4 (Critical) | 2026-08-31 |
| CVE-2026-81578 | PaperCut NG/MF | Improper access control | 8.8 (High) | 2026-08-31 |
| CVE-2026-49869 | Kestra OSS | Auth bypass to unauth RCE | 10.0 (Critical) | 2026-09-02 |
| CVE-2026-48710 | Starlette (ASGI framework) | Host header validation bypass | 6.5 (Medium) | 2026-09-02 |
| CVE-2026-59822 | LiteLLM (AI Gateway) | Auth bypass via forged header | Pending | 2026-09-02 |
The flaws that stand out
SonicWall gateways under active attack
Two SonicWall bugs led the shared list. CVE-2026-83548 is a pre-authentication SSRF rated a perfect 10.0. Paired with the command-injection flaw CVE-2026-83549, it opens a path to unauthenticated code execution. SonicWall confirmed live attacks, and Daily Cybersecurity flagged both a day before CISA. Since SMA1000 gateways face the internet, exposed units need an immediate review.
AI tools and WordPress plugins hit hardest
The four DC-exclusive flaws show why early intelligence matters. VulnCheck watched the Langflow bug draw hundreds of attacks that harvest OpenAI and AWS keys. Wordfence, meanwhile, blocked roughly 200,000 attempts on Elementor Pro and over 440,000 on the Super Forms plugin. Both plugin flaws let unauthenticated visitors upload a web shell. None of these four sit on CISA KEV yet.
What defenders should do
Prioritize by exploitation, not by score alone. First, patch the internet-facing SonicWall, JFrog, and Switchvox systems. Next, update every affected WordPress site and inspect upload folders for stray PHP files. Then patch Chrome to close the V8 drive-by bug. Finally, secure the Langflow, LiteLLM, Kestra, PaperCut, and Starlette instances on your network.
Download the full CVE dataset
This premium content is securely locked. You must upgrade your subscription to access the full threat intelligence report, including detailed mitigation steps, deep-dive analysis, and active exploitation metrics. Your attempt to inspect the DOM will only reveal this placeholder text. Please support our work to read the actual coverage.
Unlock Premium Threat Intelligence
This is a premium content. Upgrade to Pro or Team to unlock full access and remove all reading restrictions.