2 vulnerabilities across 2 products scored HIGH or above on August 12, 2026.

  • ๐ŸŸ  HIGH: 2

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-21273 (adobe/coldfusion_2025) โ€” F1: exploitable โ†’ functional, AAS: 10.7 โ†’ 12.7 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-70336 (microsoft/visual_studio_code) โ€” F1: exploitable โ†’ functional, AAS: 11.2 โ†’ 13.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-69306 (microsoft/visual_studio_code) โ€” F1: theoretical โ†’ functional, AAS: 9.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-72778 (craftcms/cms) โ€” F1: exploitable โ†’ itw, AAS: 10.3 โ†’ 13.3 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-72779 (craftcms/cms) โ€” F1: theoretical โ†’ poc, AAS: 9.8 โ†’ 12.3 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-70329 (microsoft/microsoft_365_apps_for_enterprise) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-70311 (microsoft/microsoft_365_apps_for_enterprise) โ€” F1: exploitable โ†’ functional, AAS: 9.6 โ†’ 11.6 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-49179 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62816 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62815 (microsoft/windows_11_version_23h2) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-59132 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.3 โ†’ 11.3 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62761 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62807 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62735 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62741 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62778 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62752 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62754 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62770 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62701 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-61925 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62707 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-62889 (microsoft/windows_10_version_1607) โ€” F1: exploitable โ†’ functional, AAS: 9.1 โ†’ 11.1 (HIGH โ†’ HIGH). Originally in 2026-08-11 bulletin.
  • [UPGRADED] CVE-2026-71558 (apache/fory) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-08-07 bulletin.
  • [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) โ€” F1: theoretical โ†’ poc, AAS: 9.1 โ†’ 11.6 (HIGH โ†’ HIGH). Originally in 2026-08-07 bulletin.
  • [UPGRADED] CVE-2026-65507 (sergey/aiwu) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) โ€” F1: theoretical โ†’ poc, AAS: 10.7 โ†’ 13.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-34191 (apache/apr-util) โ€” F1: exploitable โ†’ functional, AAS: 10.5 โ†’ 12.5 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-28139 (wpdreams/ajax_search_lite) โ€” F1: exploitable โ†’ functional, AAS: 10.1 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2025-15039 (wso2/wso2_identity_server) โ€” F1: theoretical โ†’ itw, AAS: 9.9 โ†’ 13.9 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-65583 (apache/cxf) โ€” F1: exploitable โ†’ functional, AAS: 9.9 โ†’ 11.9 (HIGH โ†’ HIGH). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-68079 (apache/cxf) โ€” F1: theoretical โ†’ poc, AAS: 9.6 โ†’ 12.1 (HIGH โ†’ CRITICAL). Originally in 2026-08-06 bulletin.
  • [UPGRADED] CVE-2026-48168 (mervinpraison/praisonai) โ€” F1: exploitable โ†’ functional, AAS: 10.8 โ†’ 12.8 (HIGH โ†’ CRITICAL). Originally in 2026-08-05 bulletin.

๐ŸŸ  [HIGH] red_hat/red_hat_advanced_cluster_management_for_kubernetes_2

1 CVE | CVSS 3.1: 9.9 | AAS 9.2

  • cpe:2.3:a:redhat:red_hat_advanced_cluster_management_for_kubernetes_2:*:*:*:*:*:*:*:* (>= 2.0)

Red Hat Advanced Cluster Management for Kubernetes 2 is affected by one critical vulnerability (CVE-2026-72526, CVSS 9.9) in the multicloud-integrations component. The flaw allows a tenant with Application creation permissions on the hub cluster to bypass validation in the Application propagation controller, targeting arbitrary managed clusters and forcing ArgoCD on spoke clusters to synchronize attacker-controlled manifests, ultimately enabling arbitrary code execution or privilege escalation across the managed fleet. This vulnerability is considered exploitable, so organizations running RHACM 2 should review the vendor advisory at access.redhat.com and apply available patches or mitigations immediately, paying particular attention to restricting Application CR creation permissions on hub clusters as an interim control.

Vendor Advisory


๐ŸŸ  [HIGH] phoenix_contact/axc_f_1152

1 CVE | CVSS 4.0: 9.3 | AAS 9.2

  • cpe:2.3:a:phoenix_contact:axc_f_1152:*:*:*:*:*:*:*:*

Phoenix Contact AXC F 1152 programmable logic controllers are affected by one critical vulnerability (CVE-2025-41769, CVSS 9.3) involving a buffer overflow in the PROFINET service that is present in the default configuration. An unauthenticated remote attacker can exploit this flaw to reboot the device or achieve arbitrary code execution, making this a serious risk for any industrial control environment running these controllers. Organizations using affected devices should immediately consult the vendor advisory at phoenixcontact.csaf-tp.certvde.com, apply available firmware updates, and ensure PROFINET-facing network segments are properly isolated from untrusted networks.

Vendor Advisory