30 vulnerabilities across 15 products scored HIGH or above on August 12, 2026.

  • πŸ”΄ CRITICAL: 11
  • 🟠 HIGH: 19

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-72886 (dokploy/dokploy) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72882 (dokploy/dokploy) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72901 (dokploy/dokploy) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-72737 (dokploy/dokploy) β€” F1: exploitable β†’ functional, AAS: 9.7 β†’ 11.7 (HIGH β†’ HIGH). Originally in 2026-08-10 bulletin.
  • [UPGRADED] CVE-2026-71558 (apache/fory) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-08-07 bulletin.
  • [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) β€” F1: theoretical β†’ poc, AAS: 9.1 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-08-07 bulletin.
  • [UPGRADED] CVE-2026-65507 (flavor/aiwu) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) β€” F1: theoretical β†’ poc, AAS: 10.7 β†’ 13.2 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-34191 (apache/apr-util) β€” F1: exploitable β†’ functional, AAS: 10.5 β†’ 13.7 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-28139 (ajax_search_lite/ajax_search_lite) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2025-15039 (wso2/api_control_plane) β€” F1: theoretical β†’ itw, AAS: 9.9 β†’ 13.9 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-65583 (apache/cxf) β€” F1: exploitable β†’ functional, AAS: 9.9 β†’ 11.9 (HIGH β†’ HIGH). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-68079 (apache/cxf) β€” F1: theoretical β†’ poc, AAS: 9.6 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-48168 (mervinpraison/praisonai) β€” F1: exploitable β†’ functional, AAS: 10.8 β†’ 12.8 (HIGH β†’ CRITICAL). Originally in 2026-08-05 bulletin.

πŸ”΄ [CRITICAL] fortinet/fortiweb

1 CVE | CVSS 3.1: 9.8 | AAS 14.9

  • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

Fortinet FortiWeb web application firewalls are affected by a critical authentication bypass vulnerability (CVE-2026-26035, CVSS 9.8) that allows a remote unauthenticated attacker to log into the FortiWeb GUI or CLI using arbitrary credentials. Affected versions span FortiWeb 7.0.x through 8.0.2, covering a wide range of deployments. Proof-of-concept exploit code is available, making exploitation imminent.

All organizations running FortiWeb appliances should treat this as an emergency. Apply the vendor-provided patches immediately by consulting the Fortinet advisory at FG-IR-26-158, restrict management interface access to trusted networks, and review authentication logs for any signs of unauthorized login activity.

Vendor Advisory


πŸ”΄ [CRITICAL] ibm/i

4 CVEs | CVSS 3.1: 9.9 | AAS 12.9

  • cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*

IBM i operating system versions 7.3 through 7.6 are affected by four vulnerabilities, including at least one critical remote code execution flaw via out-of-bounds write (CVSS 9.9). Functional exploit code is reported to be available, significantly elevating the risk of active exploitation against exposed systems.

Organizations running IBM i should apply patches immediately by following the guidance at the IBM support advisory. Given the critical severity and availability of working exploits, prioritize patching and review system logs for indicators of unauthorized access or anomalous activity.

Vendor Advisory


πŸ”΄ [CRITICAL] rustfs/rustfs

1 CVE | CVSS 3.1: 8.8 | AAS 12.9

  • cpe:2.3:a:rustfs:rustfs:*:*:*:*:*:*:*:*

RustFS, a Rust-based distributed object storage system, contains a critical privilege escalation vulnerability (CVE-2026-73284, CVSS 8.8) in its service account creation handler. The flaw allows an authenticated attacker to specify an arbitrary target user and create a service account with owner-level privileges, effectively escalating to full administrative control. Exploitation in the wild has been reported.

Organizations using RustFS should upgrade immediately to version 1.0.0-beta.11 or later, which resolves the issue. Audit existing service accounts for any unauthorized or unexpected entries, and restrict administrative API access to trusted networks until patching is complete.

Vendor Advisory


πŸ”΄ [CRITICAL] microsoft/prompty

1 CVE | CVSS 3.1: 10.0 | AAS 12.8

  • cpe:2.3:a:microsoft:prompty:*:*:*:*:*:*:*:*

Microsoft Prompty, a markdown-based format for LLM prompts, contains a critical remote code execution vulnerability (CVE-2026-73299, CVSS 10.0) in its TypeScript Nunjucks renderer. An attacker who can supply a crafted .prompty template file can exploit unrestricted JavaScript member access to traverse prototype chains and execute arbitrary code in the host Node.js process. Functional exploit code is available.

Teams using the Prompty library should upgrade immediately to version 0.1.5 or 2.0.0-beta.5, which restrict template evaluation. Until patched, do not process untrusted or user-supplied .prompty files, and audit any workflows where external template input is accepted.

Vendor Advisory


πŸ”΄ [CRITICAL] prowler-cloud/prowler

1 CVE | CVSS 3.1: 9.9 | AAS 12.7

  • cpe:2.3:a:prowler-cloud:prowler:*:*:*:*:*:*:*:*

Prowler, an open-source cloud security assessment platform, contains a critical remote code execution vulnerability (CVE-2026-73263, CVSS 9.9) in its Kubernetes provider connection flow. The kubeconfig validation only checked for exec-based authentication blocks but failed to block legacy GCP auth-provider entries, allowing an attacker to inject arbitrary command execution via crafted kubeconfig content submitted through the API. Functional exploit code is available.

Organizations running Prowler should upgrade to version 5.36.0 or later immediately. Until patched, restrict access to the provider connection API endpoint and audit any previously submitted kubeconfig entries for suspicious auth-provider configurations.

Vendor Advisory


πŸ”΄ [CRITICAL] budibase/budibase

1 CVE | CVSS 3.1: 9.6 | AAS 12.7

  • cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*

Budibase, an open-source low-code application platform, contains a critical SQL injection vulnerability (CVE-2026-73300, CVSS 9.6) in its MySQL integration component. The connector is configured with multiple statement execution enabled, allowing attackers to inject arbitrary SQL commands through user input fields and achieve complete database compromise. Functional exploit code is available.

Organizations using Budibase with MySQL data sources should upgrade to version 3.40.0 immediately. Until patched, restrict access to affected Budibase applications, audit database logs for suspicious multi-statement queries, and consider disabling MySQL integrations as a temporary mitigation.

Vendor Advisory


πŸ”΄ [CRITICAL] canonical/lxd

8 CVEs | CVSS 3.1: 9.9 | AAS 12.2

  • cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* (>= 5.0, < 5.0.4)
  • cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* (>= 5.1, < 5.21.2)

Canonical LXD, the system container and virtual machine manager, is affected by eight vulnerabilities, including multiple critical project restriction bypass flaws (max CVSS 9.9). The lead vulnerability allows an authenticated attacker with instance creation permissions to bypass project-level security restrictions during instance migration, circumventing controls on low-level container access, device restrictions, and network access. Functional exploit code is available for at least one of these issues.

Organizations running LXD should apply the patches referenced in the vendor pull request immediately. Review project-level restriction configurations and audit recent cross-project instance migrations for any unauthorized configuration changes or privilege escalation attempts.

Vendor Advisory


πŸ”΄ [CRITICAL] xerrors/yuxi

1 CVE | CVSS 3.1: 9.4 | AAS 12.2

  • cpe:2.3:a:xerrors:yuxi:*:*:*:*:*:*:*:* (< 0.6.2)

Yuxi, an AI-powered knowledge base and knowledge graph agent platform, contains a critical authentication bypass vulnerability (CVE-2026-50561, CVSS 9.4). The system only performs a validity check on authorization tokens without binding them to the specific deployment instance, allowing an administrator token generated on any other Yuxi deployment or local test environment to grant full backend management access. Functional exploit code is available.

Organizations running Yuxi should upgrade to version 0.6.2 or later immediately. Until patched, restrict network access to backend management interfaces and rotate any existing administrator tokens, as tokens from unrelated deployments could be used to compromise production systems.

Vendor Advisory


πŸ”΄ [CRITICAL] semaphoreui/semaphore

3 CVEs | CVSS 3.1: 9.9 | AAS 12.2

  • cpe:2.3:a:semaphoreui:semaphore:*:*:*:*:*:*:*:*

Semaphore UI, a web-based interface for managing DevOps automation tools, is affected by three vulnerabilities, including multiple critical command injection flaws (max CVSS 9.9). The lead vulnerability allows a project Manager or Owner to inject arbitrary OS commands via a crafted git repository URL, which is passed unsanitized to the git client during repository operations and scheduled commit-hash polling. Proof-of-concept exploit code is available.

Organizations running Semaphore UI should upgrade to version 2.18.17 or 2.19.5-beta2 immediately. Until patched, audit existing repository configurations for suspicious URLs and restrict project Manager and Owner roles to trusted personnel only.

Vendor Advisory


πŸ”΄ [CRITICAL] etcd-io/etcd

1 CVE | CVSS 4.0: 8.7 | AAS 12.1

  • cpe:2.3:a:etcd-io:etcd:*:*:*:*:*:*:*:* (< 3.5.33)
  • cpe:2.3:a:etcd-io:etcd:*:*:*:*:*:*:*:* (>= 3.6.0, < 3.6.14)
  • cpe:2.3:a:etcd-io:etcd:*:*:*:*:*:*:*:* (>= 3.7.0, < 3.7.1)

etcd, the widely deployed distributed key-value store used as the backbone for Kubernetes and other distributed systems, contains a critical denial-of-service vulnerability (CVE-2026-73500, CVSS 8.7). A network attacker who can reach an etcd TLS listener can open numerous TCP connections without completing the TLS handshake, causing unbounded goroutine and memory growth that can exhaust server resources and crash the etcd process. Proof-of-concept exploit code is available.

Organizations running etcd should upgrade to versions 3.5.33, 3.6.14, or 3.7.1 immediately. Until patched, restrict network access to etcd TLS listeners to trusted clients only and monitor etcd processes for abnormal memory consumption or goroutine counts.

Vendor Advisory


πŸ”΄ [CRITICAL] gitlab/gitlab

3 CVEs | CVSS 3.1: 8.7 | AAS 12.0

  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 19.0, < 19.0.6)
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 19.1, < 19.1.4)
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 19.2, < 19.2.2)

GitLab CE/EE is affected by three vulnerabilities, including multiple high-severity flaws (max CVSS 8.7), across all versions from 18.2 onward. The lead vulnerability is a cross-site scripting issue in an analytics dashboard component caused by improper neutralization of user-controlled values rendered in table cell content. Functional exploit code is available for at least one of these issues.

Organizations running self-managed GitLab instances should upgrade to versions 19.0.6, 19.1.4, or 19.2.2 immediately. Review the patch release advisory for full details on all three CVEs and monitor analytics dashboard usage logs for any indicators of exploitation.

Vendor Advisory


🟠 [HIGH] red_hat/multicluster_engine_for_kubernetes

2 CVEs | CVSS 3.1: 9.9 | AAS 11.6

  • cpe:2.3:a:redhat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:*

Red Hat Multicluster Engine for Kubernetes is affected by two vulnerabilities, including at least one critical privilege escalation flaw (max CVSS 9.9) in the cluster-curator-controller component. A local user with namespace-level access can create a specially named ClusterCurator resource to trigger the creation of a cluster-scoped ClusterRoleBinding, escalating privileges to full cluster-wide control over secrets, cluster actions, and hosted clusters. Proof-of-concept exploit code is available.

Organizations using Multicluster Engine for Kubernetes should apply Red Hat’s patches immediately and audit existing ClusterCurator resources and ClusterRoleBindings for any unauthorized or suspicious entries. Restrict namespace-level permissions for creating ClusterCurator objects until remediation is in place.

Vendor Advisory


🟠 [HIGH] getkin/kin-openapi

1 CVE | CVSS 3.1: 9.1 | AAS 11.4

  • cpe:2.3:a:getkin:kin-openapi:*:*:*:*:*:*:*:* (< 0.144.0)

kin-openapi, a widely used Go library for handling OpenAPI files, contains a high-severity authentication bypass vulnerability (CVE-2026-73501, CVSS 9.1). When applications rely on ValidationHandler as their enforcement middleware without explicitly setting an AuthenticationFunc, the library silently substitutes a no-op callback that satisfies all OpenAPI security requirements without checking credentials, allowing unauthenticated access to protected endpoints. Proof-of-concept exploit code is available.

Go application developers using kin-openapi’s ValidationHandler should upgrade to version 0.144.0 immediately. Until patched, verify that an explicit AuthenticationFunc is configured in all ValidationHandler instances and audit access logs for any unauthenticated requests to security-protected API endpoints.

Vendor Advisory


🟠 [HIGH] seriousm4x/upsnap

1 CVE | CVSS 3.1: 9.6 | AAS 11.4

  • cpe:2.3:a:seriousm4x:upsnap:*:*:*:*:*:*:*:* (< 5.4.0)

UpSnap, a Wake-on-LAN web application, contains a high-severity OS command injection vulnerability (CVE-2026-49481, CVSS 9.6) in its device management functionality. A low-privileged authenticated user can inject arbitrary OS commands through the IP or MAC address fields, which are interpolated unsanitized into wake and shutdown command templates and executed via the system shell on both Linux and Windows hosts. Proof-of-concept exploit code is available.

Organizations running UpSnap should upgrade to version 5.4.0 immediately. Until patched, restrict device management permissions to trusted administrators only and audit existing device entries for any suspicious values in the IP or MAC fields.

Vendor Advisory


🟠 [HIGH] ibm/informix_dynamic_server

1 CVE | CVSS 3.1: 8.8 | AAS 11.1

  • cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*

IBM Informix Dynamic Server contains a high-severity remote code execution vulnerability (CVE-2026-13361, CVSS 8.8) in the oninit process. An attacker can exploit an unchecked length field in the SQL interface’s sq_sgkprepare function to achieve arbitrary code execution on the database server. Proof-of-concept exploit code is available.

Organizations running IBM Informix Dynamic Server should apply the vendor patch referenced in the IBM support advisory immediately. Until patched, restrict network access to Informix listener ports to trusted clients only and monitor database server processes for anomalous activity.

Vendor Advisory