20 vulnerabilities across 10 products scored HIGH or above on July 29, 2026.

  • πŸ”΄ CRITICAL: 4
  • 🟠 HIGH: 16

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-51235 (programmervuln/cveadvisory-) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.
  • [UPGRADED] CVE-2026-65921 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.
  • [UPGRADED] CVE-2026-66014 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.
  • [UPGRADED] CVE-2026-65617 (jfrog/artifactory) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-07-27 bulletin.

πŸ”΄ [CRITICAL] ibm/websphere_application_server

1 CVE | CVSS 3.1: 9.4 | AAS 13.1

  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

IBM WebSphere Application Server β€” Critical SSRF Vulnerability

IBM WebSphere Application Server versions 8.5 and 9.0, along with WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8, are affected by one critical severity CVE (CVSS 9.4) involving a server-side request forgery vulnerability that is exploitable when the SIP container feature (sipServlet-1.1) is enabled. Organizations running WebSphere with SIP servlet functionality should treat this as an urgent priority, as SSRF at this severity level can allow attackers to reach internal services, bypass network controls, and potentially pivot deeper into backend infrastructure. Administrators should consult the vendor advisory at https://www.ibm.com/support/pages/node/7281721 immediately, apply the recommended fix, and evaluate whether the SIP container feature can be disabled in environments where it is not actively required.

Vendor Advisory


πŸ”΄ [CRITICAL] prebid/prebid-server

1 CVE | CVSS 3.1: 10.0 | AAS 12.3

  • cpe:2.3:a:prebid:prebid-server:*:*:*:*:*:*:*:*

Prebid Server β€” Critical SSRF via Bidder Adapter Parameter Injection

Prebid Server versions prior to 4.4.0 are affected by one critical severity CVE (CVSS 10.0) in which certain bidder adapters fail to properly validate host and subdomain values in user-supplied parameters, allowing attackers to craft bid requests that force the server to issue requests to arbitrary internal or external destinations. This server-side request forgery vulnerability can expose internal network services and sensitive endpoints, making it a serious risk for any organization running Prebid Server for programmatic ad auctions. Teams should upgrade to version 4.4.0 immediately and review the fix at https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3 to understand which bidder adapters were affected.

Vendor Advisory


πŸ”΄ [CRITICAL] apache/traffic_server

3 CVEs | CVSS 4.0: 9.2 | AAS 12.2

  • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*

Apache Traffic Server β€” Critical TLS/SNI Handling Crashes

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 are affected by three CVEs (max CVSS 9.2), including multiple null dereference and dangling reference flaws in TLS and SNI handling that can crash the server. Proof-of-concept exploit code is available, and organizations using Traffic Server as a reverse proxy or CDN layer should treat this as urgent given the potential for denial of service against critical traffic infrastructure. Upgrade immediately to version 9.2.15 or 10.1.4, and review the advisory at https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d for full details on all three issues.

Vendor Advisory


πŸ”΄ [CRITICAL] an_unrestricted_scorm_file_upload_vulnerability_in_koollab_lms_allowed_an_authenticated_module_designer_to_upload_a_scorm_package_containing_a_php_webshell_to_a_publicly_accessible_directory_and_execute_arbitrary_code_on_the_server./koollab_lms

1 CVE | CVSS 3.1: 9.9 | AAS 12.1

  • cpe:2.3:a:an_unrestricted_scorm_file_upload_vulnerability_in_koollab_lms_allowed_an_authenticated_module_designer_to_upload_a_scorm_package_containing_a_php_webshell_to_a_publicly_accessible_directory_and_execute_arbitrary_code_on_the_server.:koollab_lms:*:*:*:*:*:*:*:*

Koollab LMS β€” Critical Unrestricted File Upload to Remote Code Execution

Koollab LMS is affected by one critical severity CVE (CVSS 9.9) in which an authenticated user with module designer privileges can upload a SCORM package containing a PHP webshell to a publicly accessible directory, achieving arbitrary code execution on the server. This is a straightforward path to full server compromise, and any organization running Koollab LMS should treat this as an immediate priority, particularly given that the attack requires only low-privilege authenticated access. Review the advisory from the Cyber Security Agency of Singapore at https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/ for remediation guidance, and consider restricting SCORM upload permissions and auditing web-accessible directories for suspicious files as interim mitigations.

Vendor Advisory


🟠 [HIGH] apache_software_foundation/apache_traffic_server

9 CVEs | CVSS 4.0: 8.3 | AAS 11.4

  • cpe:2.3:a:apache:apache_traffic_server:*:*:*:*:*:*:*:*

Apache Traffic Server β€” High-Severity Batch Including Use-After-Free and Multiple Additional Flaws

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 are affected by nine CVEs (max CVSS 8.3), including multiple high-severity issues such as a use-after-free in the intercept plugin, with functional exploit code reported available. Organizations relying on Traffic Server for proxying or caching should prioritize this update given the breadth of issues and the availability of working exploits, which increase the likelihood of active attacks against exposed instances. Upgrade to version 9.2.15 or 10.1.4 immediately and consult the advisory at https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d for the complete list of addressed vulnerabilities.

Vendor Advisory


🟠 [HIGH] davegamble/cjson

1 CVE | CVSS 4.0: 8.7 | AAS 11.1

  • cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*

cJSON β€” High-Severity Stack Exhaustion via Recursive JSON Patch Operations

cJSON versions through 1.7.19 are affected by one high-severity CVE (CVSS 8.7) in which crafted JSON Patch documents using add and copy operations can trigger uncontrolled recursion in cJSON_Delete() and cJSON_Duplicate(), leading to stack exhaustion and denial of service. Proof-of-concept exploit code is available, and this issue is particularly concerning for any application that processes untrusted RFC 6902 JSON Patch input using the cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() functions, as cJSON is widely embedded as a lightweight dependency across IoT firmware, embedded systems, and server-side applications. Teams should monitor the upstream repository at https://github.com/DaveGamble/cJSON for a patched release and consider validating patch document depth or sandboxing JSON Patch processing as interim mitigations.

Vendor Advisory


🟠 [HIGH] kube-logging/logging-operator

1 CVE | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:kube-logging:logging-operator:*:*:*:*:*:*:*:*

Kube-Logging Logging Operator β€” Critical Configuration Injection Leading to Remote Code Execution

Kube-logging logging-operator versions prior to 6.6.0 are affected by one critical severity CVE (CVSS 9.9) in which a user with permissions to create Flow custom resources can inject arbitrary Fluentd configuration directives through unescaped CRD string values, enabling command execution inside the Fluentd aggregator pod via crafted match blocks. This is a serious container escape and lateral movement risk for any Kubernetes cluster using logging-operator, as compromising the Fluentd aggregator can expose log data across all namespaces and provide a foothold for further cluster exploitation. Upgrade to version 6.6.0 immediately per the release at https://github.com/kube-logging/logging-operator/releases/tag/6.6.0 and audit existing Flow resources for suspicious record_transformer configurations.

Vendor Advisory


🟠 [HIGH] holest/spreadsheet_price_changer_for_woocommerce_and_wp_e-commerce_–_light

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:holest:spreadsheet_price_changer_for_woocommerce_and_wp_e-commerce_light:*:*:*:*:*:*:*:*

Spreadsheet Price Changer for WooCommerce β€” Critical Unauthenticated Admin Account Creation

The Spreadsheet Price Changer for WooCommerce and WP E-commerce Light plugin for WordPress versions up to and including 2.4.37 is affected by one critical severity CVE (CVSS 9.8) in which a missing authorization check in the user_filter function allows unauthenticated attackers to create administrator accounts, leading to full site takeover. Any WordPress site running this WooCommerce pricing plugin should treat this as an emergency, as no authentication is required to exploit the flaw and the impact is complete administrative compromise. Update the plugin beyond version 2.4.37 immediately, audit your WordPress user list for unauthorized admin accounts, and review the technical details at the vendor advisory linked above.

Vendor Advisory


🟠 [HIGH] stylemixthemes/cost_calculator_builder_pro

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:stylemixthemes:cost_calculator_builder_pro:*:*:*:*:*:*:*:*

Cost Calculator Builder PRO for WordPress β€” Critical Remote Code Execution via eval Injection

The Cost Calculator Builder PRO plugin for WordPress versions up to and including 4.0.3 is affected by one critical severity CVE (CVSS 9.8) in which insufficient sanitization of order detail values allows attackers to inject arbitrary PHP code into a formula string passed to eval(), achieving remote code execution on the server. This vulnerability is exploitable by unauthenticated users submitting crafted calculator input, making any WordPress site running this plugin an immediate target for full server compromise. Update beyond version 4.0.3 as soon as a fix is available from the vendor at https://stylemixthemes.com/cost-calculator-plugin/, and consider deactivating the plugin in the interim while auditing servers for signs of exploitation.

Vendor Advisory


🟠 [HIGH] flytohub/flyto-core

1 CVE | CVSS 3.1: 10.0 | AAS 9.3

  • cpe:2.3:a:flytohub:flyto-core:*:*:*:*:*:*:*:*

Flyto2 Core β€” Critical Arbitrary File Write via Sandbox Escape

Flyto2 Core versions prior to 2.26.6 are affected by one critical severity CVE (CVSS 10.0) in which the image.download and related file-writing modules accept caller-controlled output directories without enforcing sandbox confinement, allowing attackers to write arbitrary content to any filesystem path accessible by the process. This is a maximum-severity issue that can lead to full system compromise through overwriting configuration files, injecting cron jobs, or planting webshells, and is particularly dangerous given Flyto2 Core’s role as an execution kernel for automation and AI-agent workflows where untrusted inputs are common. Upgrade to version 2.26.6 immediately per the fix at https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc and audit systems for any unexpected file modifications that may indicate prior exploitation.

Vendor Advisory