26 vulnerabilities across 13 products scored HIGH or above on August 03, 2026.
- π΄ CRITICAL: 2
- π HIGH: 24
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-67305 (freerdp/freerdp) β F1: exploitable β functional, AAS: 10.0 β 12.0 (HIGH β CRITICAL). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-67320 (axios/axios) β F1: theoretical β poc, AAS: 9.4 β 11.9 (HIGH β HIGH). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-65921 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-66014 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65617 (jfrog/artifactory) β F1: exploitable β functional, AAS: 9.2 β 11.2 (HIGH β HIGH). Originally in 2026-07-27 bulletin.
π΄ [CRITICAL] openemr/openemr
4 CVEs | CVSS 4.0: 9.4 | AAS 12.2
cpe:2.3:a:openemr:openemr:*:*:*:*:*:*:*:*
OpenEMR through version 8.2.0 is affected by four vulnerabilities, including at least one critical remote code execution flaw rated CVSS 9.4. The most severe issue allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads through the document category tree component, exploiting an unsanitized eval() call in the application’s Tree class. Proof-of-concept exploit code is publicly available, increasing the risk of near-term exploitation. Healthcare organizations and any entity running OpenEMR should treat this as an urgent priority, as the platform is widely deployed in clinical environments handling sensitive patient data. Administrators should monitor the vendor advisory at jivasecurity.com for patches and apply updates as soon as they become available, restricting administrative access and auditing admin accounts in the interim.
- π΄ CVE-2026-39932 (CVSS 4.0: 9.4)
- π΄ CVE-2026-67610 (CVSS 4.0: 8.6)
- π CVE-2026-67611 (CVSS 4.0: 8.6)
- π CVE-2026-39931 (CVSS 4.0: 8.6)
π [HIGH] krayin/laravel-crm
2 CVEs | CVSS 4.0: 9.3 | AAS 11.7
cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*
Krayin CRM version 2.2.4 is affected by two vulnerabilities, including at least one critical-severity authentication bypass rated CVSS 9.3. The most serious flaw allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted request to the installer endpoint, effectively bypassing the CanInstall middleware and achieving full account takeover without any credentials. Proof-of-concept exploit code is publicly available. Organizations using Krayin CRM should immediately review the vendor advisory at jivasecurity.com, restrict network access to the application where possible, and apply patches or mitigations as soon as they are released.
- π CVE-2026-41452 (CVSS 4.0: 9.3)
- π CVE-2026-41453 (CVSS 4.0: 8.7)
π [HIGH] openwrt/luci
2 CVEs | CVSS 4.0: 8.7 | AAS 11.6
cpe:2.3:a:openwrt:luci:*:*:*:*:*:*:*:*(< 5890760a454dad2cb00389dba2cdc5e779e0ffdd)
OpenWrt’s LuCI web interface is affected by two vulnerabilities, including at least one high-severity path traversal flaw rated CVSS 8.7 in the luci-app-bmx7 package. The most serious issue allows unauthenticated attackers to read arbitrary files accessible to the CGI process by supplying directory traversal sequences to the bmx7-info endpoint, potentially exposing sensitive system configuration and credentials. Proof-of-concept exploit code is publicly available. Network administrators running OpenWrt devices with luci-app-bmx7 should update to the patched commit referenced in the GitHub security advisory and audit any internet-exposed management interfaces immediately.
- π CVE-2026-69095 (CVSS 4.0: 8.7)
- π CVE-2026-69096 (CVSS 4.0: 8.7)
π [HIGH] sequelize/sequelize
1 CVE | CVSS 3.1: 9.8 | AAS 11.6
cpe:2.3:a:sequelize:sequelize:*:*:*:*:*:*:*:*(< 6.37.4)
Sequelize, the widely used Node.js ORM, versions prior to 6.37.4 contain a critical SQL injection vulnerability rated CVSS 9.8 that affects applications using the Oracle dialect. The flaw exists in the escape function, which fails to sanitize single quotes in string values that begin with TO_TIMESTAMP or TO_DATE, allowing attackers to inject arbitrary SQL expressions through application inputs that reach this code path. Development and application teams using Sequelize with Oracle databases should upgrade to version 6.37.4 immediately, as the vulnerability is considered readily exploitable and could lead to full database compromise.
- π CVE-2026-69240 (CVSS 3.1: 9.8)
π [HIGH] misp/cti-transmute
2 CVEs | CVSS 4.0: 8.8 | AAS 11.2
cpe:2.3:a:misp:cti-transmute:*:*:*:*:*:*:*:*
MISP’s CTI-Transmute tool is affected by two vulnerabilities, including at least one high-severity server-side request forgery flaw rated CVSS 8.8 in the PDF-generation functionality. Attackers who can supply crafted CTI content such as conversion names, descriptions, or comments can exploit WeasyPrint’s unrestricted URL-fetching behavior during Markdown-to-PDF rendering to reach internal services or exfiltrate sensitive data. A functional exploit is available, increasing the urgency for action. Organizations using CTI-Transmute should apply the patched commit referenced in the vendor advisory immediately and review any instances exposed to untrusted CTI input.
- π CVE-2026-69078 (CVSS 4.0: 8.8)
- π CVE-2026-69082 (CVSS 4.0: 8.8)
π [HIGH] adobe/adobe_campaign_classic
6 CVEs | CVSS 3.1: 10.0 | AAS 10.8
cpe:2.3:a:adobe:adobe_campaign_classic:*:*:*:*:*:*:*:*
Adobe Campaign Classic is affected by six vulnerabilities, including multiple critical-severity flaws with the highest rated CVSS 10.0. The most severe is a server-side request forgery vulnerability that can lead to privilege escalation without any user interaction, with a changed scope indicating potential impact beyond the vulnerable component itself. These flaws are considered exploitable, making prompt remediation essential. Organizations running Adobe Campaign Classic should apply the patches detailed in Adobe’s security bulletin APSB26-120 immediately and review network segmentation around Campaign Classic instances to limit exposure.
- π CVE-2026-48331 (CVSS 3.1: 10.0)
- π CVE-2026-48323 (CVSS 3.1: 10.0)
- π CVE-2026-48330 (CVSS 3.1: 10.0)
- π CVE-2026-48333 (CVSS 3.1: 9.8)
- π CVE-2026-48326 (CVSS 3.1: 9.9)
- π CVE-2026-48317 (CVSS 3.1: 9.6)
π [HIGH] siyuan-note/siyuan
3 CVEs | CVSS 4.0: 9.9 | AAS 10.8
cpe:2.3:a:siyuan-note:siyuan:*:*:*:*:*:*:*:*(< 3.7.3)
SiYuan note-taking application versions prior to 3.7.3 are affected by three vulnerabilities, including at least one critical SQL injection flaw rated CVSS 9.9. The most severe issue allows attackers to inject arbitrary SQL statements through the searchDocs API endpoint, which can be reached unauthenticated when publish mode is enabled without authentication, potentially leading to full database compromise via stacked queries on a read-write SQLite handle. Proof-of-concept exploit code is publicly available. Users and organizations running SiYuan, particularly instances with publish mode exposed to the network, should upgrade to version 3.7.3 or later immediately and restrict access to the application’s API endpoints.
- π CVE-2026-69085 (CVSS 4.0: 9.9)
- π CVE-2026-69083 (CVSS 4.0: 9.9)
- π CVE-2026-69084 (CVSS 4.0: 9.9)
π [HIGH] whiskeysockets/baileys
1 CVE | CVSS 4.0: 9.3 | AAS 10.3
cpe:2.3:a:whiskeysockets:baileys:*:*:*:*:*:*:*:*
Baileys, the popular TypeScript/JavaScript API for WhatsApp Web, versions prior to 6.7.22 and 7.0.0-rc12 contain a high-severity message spoofing vulnerability rated CVSS 9.3. Attackers can send a malicious payload to any Baileys session to trigger fake message events, spoof message keys and content, corrupt the app state sync system through fake key shares, and inject fabricated history sync data, undermining the integrity of all messages processed by the application. The vulnerability is considered readily exploitable. Developers and organizations using Baileys in their WhatsApp integrations should upgrade to version 6.7.22 or 7.0.0-rc12 immediately and review any message data that may have been processed by unpatched instances for signs of tampering.
- π CVE-2026-48063 (CVSS 4.0: 9.3)
π [HIGH] osticket/osticket
1 CVE | CVSS 3.1: 9.8 | AAS 9.6
cpe:2.3:a:osticket:osticket:*:*:*:*:*:*:*:*(< 1.18.4)
osTicket version 1.18.3 contains a critical API key generation vulnerability rated CVSS 9.8 stemming from the use of MD5 hashing with predictable inputs such as timestamps and client IP addresses. This weak entropy allows attackers who can approximate the key generation time to brute-force valid API keys within a feasible window, potentially gaining full API access to the helpdesk system. Organizations running osTicket should monitor the vendor advisory for a patched release, rotate any existing API keys as a precaution, and restrict API access to trusted network sources to limit exposure in the interim.
- π CVE-2026-38447 (CVSS 3.1: 9.8)
π [HIGH] zephyrproject/zephyr
1 CVE | CVSS 3.1: 8.2 | AAS 9.5
cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*(< 3.7.0)
The Zephyr real-time operating system contains a high-severity heap buffer overflow vulnerability rated CVSS 8.2 in the hawkBit device management client. The flaw occurs when the HTTP response callback writes a NUL terminator one byte past the end of a heap buffer that was not sized to accommodate it, which a malicious or compromised update server could exploit to corrupt heap memory on connected devices. The vulnerability is considered exploitable. Organizations deploying Zephyr-based IoT devices using hawkBit for over-the-air updates should apply the patched commit from the Zephyr project repository immediately and ensure that device-to-server communications are restricted to trusted update infrastructure.
- π CVE-2026-10849 (CVSS 3.1: 8.2)
π [HIGH] getgrav/grav
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
Grav CMS version 2.0.10 contains a high-severity path traversal vulnerability rated CVSS 8.7 in the watermark image processing functionality. An attacker with content editing privileges can craft Markdown image syntax with directory traversal sequences to read arbitrary image files outside Grav’s media sandbox, which are then composited into a carrier image and served through the application, enabling exfiltration of sensitive files from the server. The vulnerability is considered exploitable. Administrators running Grav CMS should apply the patched commit from the vendor’s GitHub repository immediately and review editor account access to limit exposure to trusted users.
- π CVE-2026-69089 (CVSS 4.0: 8.7)
π [HIGH] admidio/admidio
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:*(< 5.0.11)
Admidio versions prior to 5.0.11 contain a high-severity authentication bypass vulnerability rated CVSS 8.7 in the forum module when configured in login-only mode. The access control logic fails to validate the login-only configuration state, allowing unauthenticated attackers to read restricted forum topics and posts by directly accessing the module with read-only parameters, bypassing the intended access restrictions entirely. The vulnerability is considered exploitable. Organizations using Admidio with login-restricted forums should upgrade to version 5.0.11 immediately, as any sensitive information shared in forum discussions may be exposed to unauthorized access.
- π CVE-2026-69091 (CVSS 4.0: 8.7)
π [HIGH] misskey-dev/misskey
1 CVE | CVSS 4.0: 9.2 | AAS 9.1
cpe:2.3:a:misskey-dev:misskey:*:*:*:*:*:*:*:*(>= 12.37.0, < 2026.5.4)
Misskey, the open source federated social media platform, versions 12.37.0 through 2026.5.3 contain a high-severity vulnerability rated CVSS 9.2 in the JSON-LD signature validation and compaction process. The flaw allows spoofed ActivityPub activities to be accepted as valid, potentially enabling attackers to forge federated content and impersonate users or instances across the Fediverse. Administrators running Misskey instances should upgrade to version 2026.5.4 immediately to ensure the integrity of federated communications and prevent acceptance of forged activities.
- π CVE-2026-46713 (CVSS 4.0: 9.2)