2 vulnerabilities across 2 products scored HIGH or above on July 30, 2026.
- ๐ HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-51235 (programmervuln/cveadvisory-) โ F1: exploitable โ functional, AAS: 9.6 โ 11.6 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65921 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-66014 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65617 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
๐ [HIGH] ase/admin_and_site_enhancements_(ase)_pro
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:ase:admin_and_site_enhancements_ase_pro:*:*:*:*:*:*:*:*(< 8.9.1)
Admin and Site Enhancements (ASE) Pro plugin for WordPress versions up to and including 8.9.0 is affected by a critical remote code execution vulnerability (CVE-2026-16610, CVSS 9.8). The flaw stems from insufficient authentication on the frontend save handler combined with unsanitized user input being passed into an eval() call within the recursive_html function, allowing unauthenticated attackers to execute arbitrary code on the server. Any organization running ASE Pro on WordPress should treat this as an urgent priority โ update immediately beyond version 8.9.0 or disable the plugin until a patch is applied, and review server logs for signs of exploitation. Full details are available from the Wordfence advisory.
- ๐ CVE-2026-16610 (CVSS 3.1: 9.8)
๐ [HIGH] webpros/plesk
1 CVE | CVSS 3.1: 9.9 | AAS 10.1
cpe:2.3:a:webpros:plesk:*:*:*:*:*:*:*:*
WebPros Plesk is affected by a critical SQL injection vulnerability in its XML-RPC API (CVE-2026-58046, CVSS 9.9). A remote authenticated user with low privileges can exploit improper input neutralization to read arbitrary data from the Plesk database, potentially leading to full compromise of the hosting panel and all managed sites and services. Any organization running Plesk should apply the vendor-provided fix immediately, audit API access logs for suspicious XML-RPC activity, and review the advisory at support.plesk.com for affected versions and remediation steps.
- ๐ CVE-2026-58046 (CVSS 3.1: 9.9)