2 vulnerabilities across 1 product scored HIGH or above on August 03, 2026.
- ๐ HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-67320 (axios/axios) โ F1: theoretical โ poc, AAS: 9.4 โ 11.9 (HIGH โ HIGH). Originally in 2026-08-01 bulletin.
- [UPGRADED] CVE-2026-65921 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-66014 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
- [UPGRADED] CVE-2026-65617 (jfrog/artifactory) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-07-27 bulletin.
๐ [HIGH] misp/cti-transmute
2 CVEs | CVSS 4.0: 8.8 | AAS 9.2
cpe:2.3:a:misp:cti-transmute:*:*:*:*:*:*:*:*
MISP CTI-Transmute, an open-source tool used for converting and evaluating cyber threat intelligence content, is affected by 2 vulnerabilities rated HIGH with a CVSS score of 8.8, including at least one server-side request forgery flaw. The SSRF vulnerability exists in the PDF-generation functionality, where user-controlled CTI content rendered via WeasyPrint can trigger unrestricted URL fetching, potentially allowing an attacker to reach internal services or exfiltrate data from the host environment.
Organizations using CTI-Transmute for evaluation report generation should update immediately by applying the patched commit referenced in the vendor advisory. Any instance exposed to untrusted CTI input is at risk. Review the advisory at the linked GitHub commit for full details and verify that your deployment reflects the fix.
- ๐ CVE-2026-69078 (CVSS 4.0: 8.8)
- ๐ CVE-2026-69082 (CVSS 4.0: 8.8)