14 vulnerabilities across 11 products scored HIGH or above on August 31, 2026.
🟠 HIGH: 14 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-65641 (veeam/one) — F1: exploitable → functional, AAS: 10.4 → 12.4 (HIGH → CRITICAL). Originally in 2026-08-26 bulletin. 🟠 [HIGH] zhenorzz/goploy 1 CVE | CVSS 3.1: 9.6 | AAS 11.4
cpe:2.3:a:zhenorzz:goploy:*:*:*:*:*:*:*:* Goploy, an open-source automation deployment system by zhenorzz, is affected by one critical vulnerability (CVE-2026-53552, CVSS 9.6) involving broken access control across multiple API endpoints. The flaw allows a user with the manager role to manipulate projects outside their assigned namespace by supplying arbitrary project or file row IDs, because the backend fails to verify namespace ownership before acting on requests. A proof-of-concept exploit is publicly available. Organizations running Goploy version 1.17.5 or earlier should review the vendor advisory at the linked GitHub Security Advisory, apply any available patches or mitigations immediately, and audit project access logs for signs of unauthorized cross-namespace activity.
...