3 vulnerabilities across 3 products scored HIGH or above on September 06, 2026.

  • 🟠 HIGH: 3

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-85046 (google/chrome) β€” F1: exploitable β†’ functional, AAS: 10.6 β†’ 12.6 (HIGH β†’ CRITICAL). Originally in 2026-09-03 bulletin.

🟠 [HIGH] shabti/frontend_admin_by_dynamiapps

1 CVE | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:shabti:frontend_admin_by_dynamiapps:*:*:*:*:*:*:*:*

Frontend Admin by DynamiApps (WordPress Plugin) β€” Critical Authentication Bypass

The Frontend Admin by DynamiApps plugin for WordPress contains a critical authentication bypass vulnerability (CVE-2026-75816, CVSS 9.8) affecting all versions up to and including 3.29.12. The flaw allows unauthenticated attackers to bypass authorization checks and submit form data to arbitrary user records, enabling full account takeover β€” including administrator accounts β€” without any credentials. This is possible because the plugin fails to enforce capability or ownership checks in its pre_update_value function, and its authorization logic can be bypassed by supplying a non-numeric post identifier.

Any WordPress site running this plugin should treat this as an urgent priority. Site administrators should update to a patched version immediately or deactivate the plugin until a fix is available. Given that exploitation requires no authentication and can lead to complete site compromise, security teams should also review user accounts and site integrity for signs of unauthorized changes.

Vendor Advisory


🟠 [HIGH] tenda/cp3

1 CVE | CVSS 4.0: 10.0 | AAS 9.9

  • cpe:2.3:a:tenda:cp3:*:*:*:*:*:*:*:*

Tenda CP3 β€” Critical Remote OS Command Injection

The Tenda CP3 IP camera, specifically firmware version 27.5.57.101, is affected by a critical remotely exploitable OS command injection vulnerability (CVE-2026-86152, CVSS 10.0). The flaw exists in the automatic Wi-Fi provisioning function within the device’s Kylin component, and successful exploitation allows an attacker to execute arbitrary operating system commands on the device remotely.

Organizations deploying Tenda CP3 cameras should treat this as an immediate priority. Administrators should check for firmware updates from Tenda, restrict network access to affected devices by placing them behind firewalls or on isolated network segments, and disable remote management interfaces until a patch is confirmed available and applied.

Vendor Advisory


🟠 [HIGH] n-able/n-central

1 CVE | CVSS 4.0: 10.0 | AAS 9.9

  • cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

N-able N-central β€” Critical Pre-Authentication Remote Code Execution

N-able N-central, a widely used remote monitoring and management (RMM) platform, is affected by a critical pre-authentication remote code execution vulnerability (CVE-2026-86218, CVSS 10.0) in all versions prior to 2026.3.1.14. Because no authentication is required to exploit this flaw, any internet-exposed N-central instance is at immediate risk of full system compromise by a remote attacker.

This is an urgent priority for any organization running N-central, particularly managed service providers who rely on it to manage client environments. Administrators should update to version 2026.3.1.14 or later immediately, review systems for signs of compromise, and ensure N-central management interfaces are not unnecessarily exposed to the internet. The vendor advisory is available at the N-able security portal with additional details.

Vendor Advisory