Daily curated vulnerability bulletins from ARETIQ AI. Each bulletin highlights the day’s most critical vulnerabilities, ranked by real-world risk — not just CVSS scores.
Ranked by AAS (ARETIQ Adjusted Score) — a real-world risk score that considers exploit maturity, deployment scale, asset criticality, and remediation status.
Subscribe via JSON feed.
No EMERGENCY vulnerabilities this month.
Daily Bulletins#
3 vulnerabilities across 2 products scored HIGH or above on October 08, 2026.
🟠 HIGH: 3 🟠 [HIGH] renstillmann/super_forms_–drag&_drop_form_builder 2 CVEs | CVSS 3.1: 9.1 | AAS 9.9
cpe:2.3:a:renstillmann:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:* Super Forms – Drag & Drop Form Builder plugin for WordPress (by RensTillmann) is affected by 2 vulnerabilities, including at least one critical-severity issue rated CVSS 9.1. The most severe flaw allows unauthenticated attackers to recursively delete arbitrary directories on the server by exploiting insufficient validation of JSON field declarations in the form submission handler, where a dirname() call trivially bypasses the ABSPATH guard. All versions up to and including 6.3.316 are affected.
...
37 vulnerabilities across 15 products scored HIGH or above on October 07, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 36 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. 🔴 [CRITICAL] ibm/langflow_oss 3 CVEs | CVSS 3.1: 9.8 | AAS 12.4
cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* IBM Langflow OSS versions 1.0.0 through 1.12.2 is affected by three vulnerabilities, including at least one critical remote code execution flaw rated CVSS 9.8 that allows an attacker to execute arbitrary OS commands without authentication. Proof-of-concept exploit code is publicly available, significantly increasing the risk of active exploitation. Organizations running Langflow OSS in any capacity should treat this as an urgent priority, review the vendor advisory at https://www.ibm.com/support/pages/node/7290694, and apply available patches or mitigations immediately.
...
109 vulnerabilities across 15 products scored HIGH or above on October 06, 2026.
🟠 HIGH: 109 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. 🟠 [HIGH] payloadcms/payload 12 CVEs | CVSS 3.1: 10.0 | AAS 11.8
cpe:2.3:a:payloadcms:payload:*:*:*:*:*:*:*:* (>= 4.0.0-canary.0, < 4.0.0-canary.34) cpe:2.3:a:payloadcms:payload:*:*:*:*:*:*:*:* (>= 3.0.0, < 3.90.0) Payload CMS by payloadcms is affected by 12 vulnerabilities, including at least one critical remote code execution flaw carrying a CVSS score of 10.0. The most severe issue resides in the @payloadcms/plugin-form-builder package, where an attacker can craft a malicious form submission to achieve arbitrary code execution on the server. These vulnerabilities are confirmed exploitable.
...
12 vulnerabilities across 5 products scored HIGH or above on October 05, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 11 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. 🔴 [CRITICAL] tryghost/ghost 2 CVEs | CVSS 3.1: 8.8 | AAS 12.2
...
7 vulnerabilities across 4 products scored HIGH or above on October 04, 2026.
🟠 HIGH: 7 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. 🟠 [HIGH] wwbn/avideo 2 CVEs | CVSS 4.0: 9.3 | AAS 10.5
...
3 vulnerabilities across 3 products scored HIGH or above on October 03, 2026.
🟠 HIGH: 3 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-26 bulletin. 🟠 [HIGH] beaverbuilder/beaver_builder_page_builder_–_drag_and_drop_website_builder 1 CVE | CVSS 3.1: 9.1 | AAS 9.4
...
64 vulnerabilities across 5 products scored HIGH or above on October 02, 2026.
🟠 HIGH: 64 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) — F1: exploitable → functional, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-30 bulletin. [UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-26 bulletin. 🟠 [HIGH] apache_software_foundation/apache_thrift 49 CVEs | CVSS 4.0: 9.2 | AAS 11.8
...
21 vulnerabilities across 10 products scored HIGH or above on October 01, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 20 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-26 bulletin. [UPGRADED] CVE-2026-93577 (gitlab/gitlab) — F1: exploitable → functional, AAS: 11.9 → 13.9 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. 🔴 [CRITICAL] fortinet/fortimail 1 CVE | CVSS 3.1: 9.8 | AAS 14.9
...
20 vulnerabilities across 11 products scored HIGH or above on September 30, 2026.
🟠 HIGH: 20 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-26 bulletin. [UPGRADED] CVE-2026-93577 (gitlab/gitlab) — F1: exploitable → functional, AAS: 11.9 → 13.9 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. 🟠 [HIGH] openbsd/openbsd 1 CVE | CVSS 4.0: 9.2 | AAS 11.7
...
27 vulnerabilities across 10 products scored HIGH or above on September 29, 2026.
🟠 HIGH: 27 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-100752 (ordasoft.com/real_estate_manager_(free)_extension_for_joomla) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-09-28 bulletin. [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-26 bulletin. [UPGRADED] CVE-2026-93577 (gitlab/gitlab) — F1: exploitable → functional, AAS: 11.9 → 13.9 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. [UPGRADED] CVE-2026-75745 (adobe/experience_manager_forms) — F1: exploitable → functional, AAS: 13.8 → 15.8 (CRITICAL → CRITICAL). Originally in 2026-09-22 bulletin. [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-09-22 bulletin. 🟠 [HIGH] google/chrome 3 CVEs | CVSS 3.1: 9.6 | AAS 11.4
...