ioc_value,ioc_type,severity,description,product,source,url,date,tags,stix_indicator_id,section,confidence CVE-2026-85046,cve,CRITICAL,"Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but",Chromium V8 (Google),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-04,kev;cisa;active-exploitation,indicator--00000000-00000001-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-59822,cve,CRITICAL,BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.,LiteLLM (BerriAI),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000002-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-48710,cve,CRITICAL,"Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",Starlette (Kludex),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000003-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-49869,cve,CRITICAL,Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.,Kestra OSS (Kestra),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000004-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82329,cve,CRITICAL,JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.,Artifactory (JFrog),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000005-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-9586,cve,CRITICAL,"Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",Switchvox (Sangoma),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000006-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83548,cve,CRITICAL,SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.,SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000007-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83549,cve,CRITICAL,"SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000008-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82078,cve,CRITICAL,PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000009-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-81578,cve,CRITICAL,PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000010-0000-0000-0000-000000000000,IP ADDRESS,100 8.4.0.2,ipv4-addr,HIGH,C2/infrastructure in threat context: CISA KEV: CVE-2026-85046 - Google: Chromium V8,,Article: CISA KEV: CVE-2026-85046 - Google: Chrom...,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,,ip;infrastructure,indicator--00000000-00000011-0000-0000-0000-000000000000,IP ADDRESS,80 8.4.0.2,ipv4-addr,HIGH,C2/infrastructure in threat context: CISA KEV: CVE-2026-48710 - Kludex: Starlette,,Article: CISA KEV: CVE-2026-48710 - Kludex: Starl...,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,,ip;infrastructure,indicator--00000000-00000012-0000-0000-0000-000000000000,PHISHING URL,80 https://www.nehsbe.cn/ww/,other,CRITICAL,Active phishing URL: https://www.nehsbe.cn/ww/,,OpenPhish,https://www.nehsbe.cn/ww/,,phishing;openphish,indicator--00000000-00000013-0000-0000-0000-000000000000,PHISHING URL,100 http://www.nehsbe.cn/,other,CRITICAL,Active phishing URL: http://www.nehsbe.cn/,,OpenPhish,http://www.nehsbe.cn/,,phishing;openphish,indicator--00000000-00000014-0000-0000-0000-000000000000,PHISHING URL,100 https://fb-meta-verified-47091.vercel.app/,other,CRITICAL,Active phishing URL: https://fb-meta-verified-47091.vercel.app/,,OpenPhish,https://fb-meta-verified-47091.vercel.app/,,phishing;openphish,indicator--00000000-00000015-0000-0000-0000-000000000000,PHISHING URL,100 https://www.fb-meta-verified-47091.vercel.app/,other,CRITICAL,Active phishing URL: https://www.fb-meta-verified-47091.vercel.app/,,OpenPhish,https://www.fb-meta-verified-47091.vercel.app/,,phishing;openphish,indicator--00000000-00000016-0000-0000-0000-000000000000,PHISHING URL,100 https://samaoluwasegun-dev.github.io/alexhoffmannboa/,other,CRITICAL,Active phishing URL: https://samaoluwasegun-dev.github.io/alexhoffmannboa/,,OpenPhish,https://samaoluwasegun-dev.github.io/alexhoffmannboa/,,phishing;openphish,indicator--00000000-00000017-0000-0000-0000-000000000000,PHISHING URL,100 http://comcastsurvey.weebly.com/,other,CRITICAL,Active phishing URL: http://comcastsurvey.weebly.com/,,OpenPhish,http://comcastsurvey.weebly.com/,,phishing;openphish,indicator--00000000-00000018-0000-0000-0000-000000000000,PHISHING URL,100 https://pink-porcupine-845141.hostingersite.com/?naps,other,CRITICAL,Active phishing URL: https://pink-porcupine-845141.hostingersite.com/?naps,,OpenPhish,https://pink-porcupine-845141.hostingersite.com/?naps,,phishing;openphish,indicator--00000000-00000019-0000-0000-0000-000000000000,PHISHING URL,100 https://ldgre-lives.pages.dev/,other,CRITICAL,Active phishing URL: https://ldgre-lives.pages.dev/,,OpenPhish,https://ldgre-lives.pages.dev/,,phishing;openphish,indicator--00000000-00000020-0000-0000-0000-000000000000,PHISHING URL,100 http://tiny.cc/rblxprivateserver,other,CRITICAL,Active phishing URL: http://tiny.cc/rblxprivateserver,,OpenPhish,http://tiny.cc/rblxprivateserver,,phishing;openphish,indicator--00000000-00000021-0000-0000-0000-000000000000,DOMAIN,100 www.nehsbe,domain-name,CRITICAL,Phishing domain: www.nehsbe,,OpenPhish,https://www.nehsbe.cn/ww/,,phishing;openphish;domain,indicator--00000000-00000022-0000-0000-0000-000000000000,DOMAIN,100 fb-meta-verified-47091.vercel,domain-name,CRITICAL,Phishing domain: fb-meta-verified-47091.vercel,,OpenPhish,https://fb-meta-verified-47091.vercel.app/,,phishing;openphish;domain,indicator--00000000-00000023-0000-0000-0000-000000000000,DOMAIN,100 www.fb,domain-name,CRITICAL,Phishing domain: www.fb,,OpenPhish,https://www.fb-meta-verified-47091.vercel.app/,,phishing;openphish;domain,indicator--00000000-00000024-0000-0000-0000-000000000000,DOMAIN,100 samaoluwasegun-dev.github,domain-name,CRITICAL,Phishing domain: samaoluwasegun-dev.github,,OpenPhish,https://samaoluwasegun-dev.github.io/alexhoffmannboa/,,phishing;openphish;domain,indicator--00000000-00000025-0000-0000-0000-000000000000,DOMAIN,100 comcastsurvey.weebly,domain-name,CRITICAL,Phishing domain: comcastsurvey.weebly,,OpenPhish,http://comcastsurvey.weebly.com/,,phishing;openphish;domain,indicator--00000000-00000026-0000-0000-0000-000000000000,DOMAIN,100 pink-porcupine-845141.hostingersite,domain-name,CRITICAL,Phishing domain: pink-porcupine-845141.hostingersite,,OpenPhish,https://pink-porcupine-845141.hostingersite.com/?naps,,phishing;openphish;domain,indicator--00000000-00000027-0000-0000-0000-000000000000,DOMAIN,100 ldgre-lives.pages,domain-name,CRITICAL,Phishing domain: ldgre-lives.pages,,OpenPhish,https://ldgre-lives.pages.dev/,,phishing;openphish;domain,indicator--00000000-00000028-0000-0000-0000-000000000000,DOMAIN,100 tiny.cc,domain-name,CRITICAL,Phishing domain: tiny.cc,,OpenPhish,http://tiny.cc/rblxprivateserver,,phishing;openphish;domain,indicator--00000000-00000029-0000-0000-0000-000000000000,DOMAIN,100 https-wwwv-roblox.co,domain-name,CRITICAL,Phishing domain: https-wwwv-roblox.co,,OpenPhish,http://https-wwwv-roblox.co/login?returnUrl=288280197,,phishing;openphish;domain,indicator--00000000-00000030-0000-0000-0000-000000000000,DOMAIN,100