10 vulnerabilities across 9 products scored HIGH or above on August 07, 2026.

  • πŸ”΄ CRITICAL: 1
  • 🟠 HIGH: 9

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-67305 (freerdp/freerdp) β€” F1: exploitable β†’ functional, AAS: 10.0 β†’ 12.0 (HIGH β†’ CRITICAL). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-15988 (suspended_starter/ai_engine) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-08-01 bulletin.
  • [UPGRADED] CVE-2026-67320 (axios/axios) β€” F1: theoretical β†’ poc, AAS: 9.4 β†’ 11.9 (HIGH β†’ HIGH). Originally in 2026-08-01 bulletin.

πŸ”΄ [CRITICAL] wordpress/wordpress

1 CVE | CVSS 4.0: 8.9 | AAS 13.6

  • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* (< 7.0.3)

WordPress core is affected by a critical pre-authentication reflected cross-site scripting vulnerability on the login screen (CVE-2026-64638, CVSS 8.9). Under certain conditions involving social engineering and explicit victim interaction, this flaw can be escalated to remote code execution via a malicious third-party site. A proof-of-concept exploit is publicly available. All versions of WordPress prior to 7.0.3 are affected, making this relevant to virtually every organization running a WordPress site. Administrators should update to WordPress 7.0.3 immediately and review the vendor advisory at HackerOne for additional details.

Vendor Advisory


🟠 [HIGH] hkuds/lightrag

1 CVE | CVSS 3.1: 9.8 | AAS 11.6

  • cpe:2.3:a:hkuds:lightrag:*:*:*:*:*:*:*:* (< 1.5.5rc1)

LightRAG, an open-source retrieval-augmented generation framework by HKUDS, is affected by a critical vulnerability (CVE-2026-61808, CVSS 9.8) in which the API server binds to all network interfaces with authentication disabled by default. An unauthenticated remote attacker can exploit this to read indexed documents, upload or delete content, modify the knowledge graph, cancel pipelines, and consume LLM resources. All deployments through version 1.5.4 are affected, and teams running LightRAG should upgrade to version 1.5.5rc1 or later immediately, and review network access controls to ensure the API is not exposed to untrusted networks.

Vendor Advisory


🟠 [HIGH] pipeboard-co/meta-ads-mcp

1 CVE | CVSS 3.1: 9.1 | AAS 11.2

  • cpe:2.3:a:pipeboard-co:meta-ads-mcp:*:*:*:*:*:*:*:*

Meta Ads MCP, an MCP server by Pipeboard that enables AI assistants to manage Meta advertising campaigns, is affected by a critical authentication bypass vulnerability (CVE-2026-48039, CVSS 9.1). The authentication middleware unconditionally forwards unauthenticated HTTP requests to downstream tool handlers, allowing any network-reachable attacker to invoke MCP tools without credentials and potentially operate against Meta Ads accounts using the server’s configured access token. Organizations running versions prior to 1.0.109 should upgrade immediately and audit their environments for any unauthorized access to Meta Ads resources.

Vendor Advisory


🟠 [HIGH] apache_software_foundation/apache_fory

2 CVEs | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:apache:apache_fory:*:*:*:*:*:*:*:* (>= 0.14.0, < 1.5.0)

Apache Fory, a serialization framework by the Apache Software Foundation, is affected by 2 vulnerabilities (CVE-2026-71558, CVE-2026-71560), including at least one rated CVSS 9.8. The most severe is a heap type confusion flaw in C++ deserialization where crafted payloads can bypass type compatibility checks during polymorphic smart-pointer handling, potentially leading to denial of service or arbitrary code execution. Organizations using Apache Fory C++ versions 0.14.0 through 1.4.x should upgrade to version 1.5.0 immediately and review the vendor advisory for details on both issues.

Vendor Advisory


🟠 [HIGH] gitroomhq/postiz-app

1 CVE | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:gitroomhq:postiz-app:*:*:*:*:*:*:*:* (< 1.0.18)

Postiz, an open-source social media scheduling tool by Gitroomhq, is affected by a critical unauthenticated path traversal vulnerability (CVE-2026-19264, CVSS 9.3). The media-serving route fails to normalize URL-encoded path segments, allowing a remote unauthenticated attacker to use encoded directory traversal sequences to read arbitrary files from the server’s filesystem. Organizations running Postiz with local media storage should consult the vendor advisory at gadvisory.org for patching guidance and immediately restrict network access to affected instances until a fix is applied.

Vendor Advisory


🟠 [HIGH] microsoft/teams

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:microsoft:teams:-:*:*:*:*:*:*:*

Microsoft Teams is affected by a critical missing authorization vulnerability (CVE-2026-65667, CVSS 10.0) that allows an unauthorized attacker to elevate privileges over a network without any user interaction. Given the maximum severity rating and the ubiquity of Teams across enterprise environments, this issue should be treated as an urgent priority for all organizations. Security teams should review the Microsoft Security Response Center advisory immediately, apply any available updates, and monitor for indicators of exploitation in their environments.

Vendor Advisory


🟠 [HIGH] kata-containers/kata-containers

1 CVE | CVSS 3.1: 9.6 | AAS 9.9

  • cpe:2.3:a:kata-containers:kata-containers:*:*:*:*:*:*:*:* (< 4.0.0)

Kata Containers, an open-source lightweight VM runtime for container isolation, is affected by a critical host code execution vulnerability (CVE-2026-50540, CVSS 9.6) in versions prior to 4.0.0. The kata-runtime accepts an arbitrary configuration path via a pod annotation and loads the referenced TOML file from the host without validation, allowing an attacker who can place a file at a host-visible path to supply a malicious configuration and achieve code execution on the host, breaking container isolation entirely. Organizations using Kata Containers should upgrade to version 4.0.0 immediately, as this vulnerability undermines the core security boundary the project is designed to provide.

Vendor Advisory


🟠 [HIGH] microsoft/planetary_computer

1 CVE | CVSS 3.1: 10.0 | AAS 9.3

  • cpe:2.3:a:microsoft:planetary_computer:-:*:*:*:pro:*:*:*

Microsoft Planetary Computer Pro is affected by a critical missing authentication vulnerability (CVE-2026-63508, CVSS 10.0) that allows an unauthorized attacker to elevate privileges over a network by accessing a critical function without any authentication. The maximum severity rating indicates this flaw is trivially exploitable with no user interaction or special conditions required. Organizations using Planetary Computer Pro should consult the Microsoft Security Response Center advisory immediately for remediation guidance and verify whether their deployments have been exposed to unauthorized access.

Vendor Advisory


🟠 [HIGH] microsoft/windows_admin_center

1 CVE | CVSS 3.1: 9.8 | AAS 9.1

  • cpe:2.3:a:microsoft:windows_admin_center:-:*:*:*:*:*:*:*

Microsoft 365 Admin Center is affected by a critical improper cryptographic signature verification vulnerability (CVE-2026-62873, CVSS 9.8) that allows an unauthorized attacker to elevate privileges over a network. The flaw enables bypassing signature validation without authentication, and while no public exploit has been observed yet, the critical severity and network-accessible attack vector make this a high-priority concern for any organization using Microsoft 365 administration services. Security teams should review the Microsoft Security Response Center advisory immediately and apply any available updates or mitigations.

Vendor Advisory