Weekly Security Roundup: August 31 to September 13, 2026

Make Sherlock Forensics your preferred source in Google Search

Weekly security briefing from Sherlock Forensics covering August 31 to September 13, 2026. 17 vulnerabilities analyzed: 16 critical (CVSS 9.0+) and 1 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 10 vulnerabilities this week including Traefik Path Traversal (CVSS 10.0 CRITICAL) (CVSS 10.0). Mozilla Firefox had 4 vulnerabilities this week including Mozilla Firefox and Thunderbird Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8). Apache got hit with a CVSS 9.6 for Apache Camel / Undertow Improper Input Validation (CVSS 9.6 CRITICAL).

We tracked 17 vulnerabilities this week. 16 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

10 vulnerabilities across Other products this week. The worst: CVE-2026-48020 (CVSS 10.0) lets attackers run code on your systems. Patch now if you run Other.

  • CVE-2026-48020: Traefik Path Traversal (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2025-15379: MLflow OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2026-72765: N8N Code Injection (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2026-9698: Perl DBI Buffer Overflow (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-9586: Switchvox SQL Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-73487: Flowise Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-73373: Joomla! Unrestricted File Upload (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-41242: protobufjs Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-19586: TP-Link Omada Gateway OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-59822: LiteLLM Authentication Bypass (CVSS 8.2 HIGH) (CVSS 8.2)

Mozilla Firefox: 4 Critical Flaws at Once

4 vulnerabilities across Mozilla Firefox products this week. The worst: CVE-2026-84143 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Mozilla Firefox.

  • CVE-2026-84143: Mozilla Firefox and Thunderbird Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-84142: Mozilla Firefox Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-84141: Mozilla Firefox Integer Overflow (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-84135: Mozilla Firefox Mobile Improper Input Validation (CVSS 9.8 CRITICAL) (CVSS 9.8)

Apache Hit With CVSS 9.6

CVE-2025-12543 scores a 9.6. Apache lets attackers run code on your systems.

  • CVE-2025-12543: Apache Camel / Undertow Improper Input Validation (CVSS 9.6 CRITICAL) (CVSS 9.6)

GitLab Hit With CVSS 9.4

CVE-2026-19478 scores a 9.4. GitLab lets attackers run code on your systems.

  • CVE-2026-19478: GitLab Code Injection (CVSS 9.4 CRITICAL) (CVSS 9.4)

Microsoft Hit With CVSS 9.1

CVE-2025-13872 scores a 9.1. Microsoft lets attackers run code on your systems.

  • CVE-2025-13872: ObjectPlanet Opinio Server-Side Request Forgery (CVSS 9.1 CRITICAL) (CVSS 9.1)

By the Numbers

Total CVEs analyzed17
Critical (9.0+)16
High (7.0-8.9)1
Remote code execution17
Authentication bypass0
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 9 critical-severity issues patched this week.
  2. Mozilla Firefox: Update immediately. 4 critical-severity issues patched this week.
  3. Apache: Update immediately. 1 critical-severity issues patched this week.
  4. GitLab: Update immediately. 1 critical-severity issues patched this week.
  5. Microsoft: Update immediately. 1 critical-severity issues patched this week.