2 vulnerabilities across 2 products scored HIGH or above on August 02, 2026.
- π HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-65921 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-66014 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65617 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
π [HIGH] go-vikunja/vikunja
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:go-vikunja:vikunja:*:*:*:*:*:*:*:*(>= 0.24.0, < 2.3.1)
Vikunja β Broken Authorization in Task-Collection Endpoint (HIGH)
Vikunja versions 0.24.0 through 2.3.0 are affected by one high-severity vulnerability (CVE-2026-68582, CVSS 9.3). The flaw is a broken object level authorization (BOLA) issue in the task-collection endpoint, where the application fails to verify that the caller is authorized for the requested project view. An attacker holding any link-share token can manipulate the URL path to access task data from unauthorized project views, bypassing intended access controls. Organizations running self-hosted Vikunja instances for project and task management should treat this as a priority remediation item, as the vulnerability is considered exploitable. Administrators should update to a patched version immediately and review the vendor advisory at the linked GitHub Security Advisory for further guidance.
- π CVE-2026-68582 (CVSS 4.0: 9.3)
π [HIGH] freerdp/freerdp
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*(< 3.30.0)
FreeRDP β Heap-Based Buffer Overflow via Malicious RDP Server (HIGH)
FreeRDP versions 3.29.0 and earlier are affected by one high-severity vulnerability (CVE-2026-68579, CVSS 8.7). The flaw is a heap-based buffer overflow in the Windows clipboard client’s CliprdrStream_Read function, where a malicious or compromised RDP server can supply an oversized file contents response that overflows a fixed-size caller buffer during an OLE paste operation. This can lead to remote code execution on the client system connecting to the attacker-controlled server. Organizations and individuals using FreeRDP on Windows for remote desktop connectivity should prioritize this update, as the vulnerability is considered exploitable. Upgrade to FreeRDP 3.30.0 or later immediately and review the vendor’s commit linked in the advisory for technical details.
- π CVE-2026-68579 (CVSS 4.0: 8.7)