Top 5 Cybersecurity News Stories September 4, 2026

This week’s Cybersecurity News Stories September 4, 2026 illustrate a consistent challenge: the gap between a protective measure and what that measure actually closes. SonicWall enterprise remote-access appliances confirmed actively exploited via a zero-day chain requiring no credentials and no user interaction. Microsoft Exchange Server 2016 deployments without Extended Security Update eligibility facing an authentication…

Read More

JFrog Artifactory Authentication Bypass Exploited

JFrog Artifactory Authentication Bypass Exploited

A JFrog Artifactory authentication bypass is now under active exploitation: attackers are minting themselves unauthenticated administrator tokens on self-hosted Artifactory instances just days after JFrog disclosed the flaw. Tracked as CVE-2026-82329 (CVSS 9.8), the bug sits in Artifactory’s default, out-of-the-box configuration — no misconfiguration required, no credentials needed. What Happened JFrog disclosed the JFrog Artifactory…

Read More