2 vulnerabilities across 2 products scored HIGH or above on August 02, 2026.
- π HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-67305 (freerdp/freerdp) β F1: exploitable β functional, AAS: 10.0 β 12.0 (HIGH β CRITICAL). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-67320 (axios/axios) β F1: theoretical β poc, AAS: 9.4 β 11.9 (HIGH β HIGH). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-65921 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-66014 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65617 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
π [HIGH] go-vikunja/vikunja
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:go-vikunja:vikunja:*:*:*:*:*:*:*:*
Vikunja β Broken Object Level Authorization (1 CVE, CVSS 9.3 HIGH)
Vikunja versions 0.24.0 through 2.3.0 are affected by a critical broken object level authorization vulnerability (CVE-2026-68582) in the task-collection endpoint. The flaw allows a holder of any link-share token to access task data from unauthorized project views because the endpoint fails to verify the caller’s authorization against the view specified in the URL path. Teams running self-hosted Vikunja instances for project and task management should prioritize this update, as the vulnerability is considered exploitable and could lead to unauthorized disclosure of project data across trust boundaries. Administrators should upgrade to a patched version immediately and review the vendor advisory at the linked GitHub security page for remediation details.
- π CVE-2026-68582 (CVSS 4.0: 9.3)
π [HIGH] freerdp/freerdp
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
FreeRDP β Heap-Based Buffer Overflow via Clipboard (1 CVE, CVSS 8.7 HIGH)
FreeRDP versions 3.29.0 and earlier are affected by a heap-based buffer overflow vulnerability (CVE-2026-68579) in the Windows clipboard client’s CliprdrStream_Read function. A malicious or compromised RDP server can exploit this flaw by returning an oversized clipboard file-content response during an OLE paste operation, causing a buffer overflow on the client that could lead to remote code execution. Organizations using FreeRDP on Windows for remote desktop connectivity should upgrade to version 3.30.0 or later immediately and review the vendor’s commit at the linked advisory for full technical details.
- π CVE-2026-68579 (CVSS 4.0: 8.7)