2 vulnerabilities across 1 product scored HIGH or above on August 05, 2026.

  • 🟠 HIGH: 2

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-67305 (freerdp/freerdp) β€” F1: exploitable β†’ functional, AAS: 10.0 β†’ 12.0 (HIGH β†’ CRITICAL). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-67320 (axios/axios) β€” F1: theoretical β†’ poc, AAS: 9.4 β†’ 11.9 (HIGH β†’ HIGH). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-48449 (adobe/campaign_classic) β€” F1: exploitable β†’ functional, AAS: 10.2 β†’ 12.8 (HIGH β†’ CRITICAL). Originally in 2026-07-30 bulletin.

🟠 [HIGH] opensips/opensips

2 CVEs | CVSS 4.0: 8.7 | AAS 9.6

  • cpe:2.3:a:opensips:opensips:*:*:*:*:*:*:*:* (< 3.6.6)
  • cpe:2.3:a:opensips:opensips:*:*:*:*:*:*:*:* (>= 4.0.0, < 4.0.0-rc1)

OpenSIPS SIP Server β€” HIGH Severity (CVSS 8.7)

OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1 are affected by 2 vulnerabilities, including multiple denial-of-service issues. The lead vulnerability involves malformed SDP bandwidth lines that corrupt parsed metadata, causing worker process crashes when modules such as dialog or QoS attempt to clone the corrupted state. These flaws are considered exploitable and could allow remote attackers to disrupt SIP infrastructure without authentication. Organizations running OpenSIPS for VoIP or unified communications should upgrade to version 3.6.6 or 4.0.0-rc1 immediately and review the vendor advisory linked from the project’s GitHub repository for patch details.

Vendor Advisory