Daily curated vulnerability bulletins from ARETIQ AI. Each bulletin highlights the day’s most critical vulnerabilities, ranked by real-world risk — not just CVSS scores.
Ranked by AAS (ARETIQ Adjusted Score) — a real-world risk score that considers exploit maturity, deployment scale, asset criticality, and remediation status.
Subscribe via JSON feed.
No EMERGENCY vulnerabilities this month.
Daily Bulletins#
10 vulnerabilities across 9 products scored HIGH or above on August 07, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 9 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-67305 (freerdp/freerdp) — F1: exploitable → functional, AAS: 10.0 → 12.0 (HIGH → CRITICAL). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. 🔴 [CRITICAL] wordpress/wordpress 1 CVE | CVSS 4.0: 8.9 | AAS 13.6
...
29 vulnerabilities across 15 products scored HIGH or above on August 06, 2026.
🟠 HIGH: 29 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-67305 (freerdp/freerdp) — F1: exploitable → functional, AAS: 10.0 → 12.0 (HIGH → CRITICAL). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-48449 (adobe/campaign) — F1: exploitable → functional, AAS: 10.2 → 12.6 (HIGH → CRITICAL). Originally in 2026-07-30 bulletin. 🟠 [HIGH] wso2/wso2_api_manager 2 CVEs | CVSS 3.1: 9.8 | AAS 11.4
...
19 vulnerabilities across 15 products scored HIGH or above on August 05, 2026.
🟠 HIGH: 19 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-48449 (adobe/campaign) — F1: exploitable → functional, AAS: 10.2 → 12.8 (HIGH → CRITICAL). Originally in 2026-07-30 bulletin. 🟠 [HIGH] mervinpraison/praisonai 1 CVE | CVSS 3.1: 10.0 | AAS 10.8
...
38 vulnerabilities across 14 products scored HIGH or above on August 04, 2026.
🟠 HIGH: 38 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-67305 (freerdp/freerdp) — F1: exploitable → functional, AAS: 10.0 → 12.0 (HIGH → CRITICAL). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-48449 (adobe/campaign_classic) — F1: exploitable → functional, AAS: 10.2 → 12.8 (HIGH → CRITICAL). Originally in 2026-07-30 bulletin. 🟠 [HIGH] cinnamon/kotaemon 1 CVE | CVSS 4.0: 9.3 | AAS 11.6
...
26 vulnerabilities across 13 products scored HIGH or above on August 03, 2026.
🔴 CRITICAL: 2 🟠 HIGH: 24 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-67305 (freerdp/freerdp) — F1: exploitable → functional, AAS: 10.0 → 12.0 (HIGH → CRITICAL). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🔴 [CRITICAL] openemr/openemr 4 CVEs | CVSS 4.0: 9.4 | AAS 12.2
...
2 vulnerabilities across 2 products scored HIGH or above on August 02, 2026.
🟠 HIGH: 2 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-67305 (freerdp/freerdp) — F1: exploitable → functional, AAS: 10.0 → 12.0 (HIGH → CRITICAL). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-67320 (axios/axios) — F1: theoretical → poc, AAS: 9.4 → 11.9 (HIGH → HIGH). Originally in 2026-08-01 bulletin. [UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🟠 [HIGH] go-vikunja/vikunja 1 CVE | CVSS 4.0: 9.3 | AAS 9.7
...
10 vulnerabilities across 4 products scored HIGH or above on August 01, 2026.
🟠 HIGH: 10 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🟠 [HIGH] freerdp/freerdp 6 CVEs | CVSS 4.0: 9.4 | AAS 10.0
...
13 vulnerabilities across 7 products scored HIGH or above on July 31, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 12 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🔴 [CRITICAL] codeigniter4/codeigniter4 2 CVEs | CVSS 3.1: 9.8 | AAS 12.3
...
25 vulnerabilities across 15 products scored HIGH or above on July 30, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 24 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🔴 [CRITICAL] somta/juggle 1 CVE | CVSS 4.0: 9.3 | AAS 12.0
...
20 vulnerabilities across 10 products scored HIGH or above on July 29, 2026.
🔴 CRITICAL: 4 🟠 HIGH: 16 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-51235 (programmervuln/cveadvisory-) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65921 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-66014 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. [UPGRADED] CVE-2026-65617 (jfrog/artifactory) — F1: exploitable → functional, AAS: 9.2 → 11.2 (HIGH → HIGH). Originally in 2026-07-27 bulletin. 🔴 [CRITICAL] ibm/websphere_application_server 1 CVE | CVSS 3.1: 9.4 | AAS 13.1
...