3 vulnerabilities across 3 products scored HIGH or above on August 06, 2026.

  • ๐ŸŸ  HIGH: 3

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) โ€” F1: exploitable โ†’ functional, AAS: 9.6 โ†’ 11.6 (HIGH โ†’ HIGH). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-67320 (axios/axios) โ€” F1: theoretical โ†’ poc, AAS: 9.4 โ†’ 11.9 (HIGH โ†’ HIGH). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-48449 (adobe/campaign) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.8 (HIGH โ†’ CRITICAL). Originally in 2026-07-30 bulletin.

๐ŸŸ  [HIGH] wso2/wso2_api_manager

1 CVE | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*

WSO2 API Manager is affected by one critical vulnerability (CVE-2026-1728, CVSS 9.8) involving insufficient token restrictions that allow a low-privileged authenticated user to access product-level Admin REST APIs, potentially leading to full administrative account takeover. Organizations running WSO2 API Manager or related WSO2 products should treat this as high priority, as the flaw is considered exploitable and could allow any authenticated user to escalate to full admin control.

Security teams should review the vendor advisory at security.docs.wso2.com for affected versions and apply available patches or mitigations immediately. In the interim, monitor Admin REST API access logs for anomalous activity from low-privileged accounts and restrict network-level access to administrative endpoints where feasible.

Vendor Advisory


๐ŸŸ  [HIGH] wso2/wso2_universal_gateway

1 CVE | CVSS 3.1: 10.0 | AAS 10.7

  • cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*

WSO2 Universal Gateway is affected by one critical vulnerability (CVE-2026-5430, CVSS 10.0) in its JWT authentication mechanism, which improperly accepts tokens signed with algorithms outside those explicitly configured. An attacker can craft a JWT using an unsupported signing algorithm to bypass authentication entirely, potentially gaining unauthorized access up to and including administrative account takeover without requiring any prior credentials.

Organizations deploying WSO2 Universal Gateway should treat this as an urgent priority given the maximum severity rating and network-accessible attack vector. Review the vendor advisory at security.docs.wso2.com for affected versions and apply patches immediately, and audit access logs for any anomalous authentication activity that may indicate prior exploitation.

Vendor Advisory


๐ŸŸ  [HIGH] wso2/wso2_identity_server

1 CVE | CVSS 3.1: 9.4 | AAS 9.9

  • cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* (>= 5.2.0)

WSO2 Identity Server is affected by one critical vulnerability (CVE-2025-15039, CVSS 9.4) in its Conditional Authentication (Adaptive Authentication) scripting engine. The flaw allows an attacker to bypass intermediate authentication steps in multi-factor authentication flows by exploiting how the system handles callbacks and re-execution of authentication steps, potentially resulting in full unauthorized access to targeted user accounts.

Organizations using WSO2 Identity Server with multi-step or adaptive authentication configurations should treat this as high priority, as it directly undermines MFA protections. Review the vendor advisory at security.docs.wso2.com for affected versions and apply patches promptly, and audit authentication logs for any sign of step-skipping or anomalous login patterns.

Vendor Advisory