38 vulnerabilities across 15 products scored HIGH or above on August 13, 2026.
- ๐ด CRITICAL: 18
- ๐ HIGH: 20
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-17083 (ibm/i) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-08-12 bulletin.
- [UPGRADED] CVE-2026-72886 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72882 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72901 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72737 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 9.7 โ 11.7 (HIGH โ HIGH). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-71558 (apache/fory) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) โ F1: theoretical โ poc, AAS: 9.1 โ 11.6 (HIGH โ HIGH). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-65507 (flavor/aiwu) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) โ F1: theoretical โ poc, AAS: 10.7 โ 13.2 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-34191 (apache/apr-util) โ F1: exploitable โ functional, AAS: 10.5 โ 13.7 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-28139 (ajax_search_lite/ajax_search_lite) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2025-15039 (wso2/api_control_plane) โ F1: theoretical โ itw, AAS: 9.9 โ 13.9 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-65583 (apache/cxf) โ F1: exploitable โ functional, AAS: 9.9 โ 11.9 (HIGH โ HIGH). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-68079 (apache/cxf) โ F1: theoretical โ poc, AAS: 9.6 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
๐ด [CRITICAL] miniorange/miniorange_otp_verification
1 CVE | CVSS 3.1: 9.8 | AAS 12.9
cpe:2.3:a:miniorange:miniorange_otp_verification:*:*:*:*:*:*:*:*
miniOrange OTP Verification plugin for WordPress versions 5.5.1 and earlier is affected by a critical unauthenticated privilege escalation vulnerability (CVE-2026-61967, CVSS 9.8). A functional exploit exists, meaning attackers can escalate privileges on vulnerable WordPress sites without any authentication. WordPress administrators running this plugin should update immediately to a patched version and review site accounts for any unauthorized privilege changes. Refer to the Patchstack advisory for patch details and additional guidance.
- ๐ด CVE-2026-61967 (CVSS 3.1: 9.8)
๐ด [CRITICAL] postgresql/postgresql
16 CVEs | CVSS 3.1: 8.8 | AAS 12.6
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
PostgreSQL is affected by 16 vulnerabilities, including multiple with functional exploits and a maximum CVSS of 8.8. Among the most critical is CVE-2026-18408, which allows a malicious superuser on an origin server to inject arbitrary code that executes during dump restoration via pg_dump, pg_dumpall, or pg_restore, bypassing the \restrict meta-command fix introduced for a prior CVE. Database administrators running PostgreSQL should apply the latest security updates immediately, audit backup and restore workflows for exposure, and consult the PostgreSQL security advisories for version-specific remediation guidance.
- ๐ด CVE-2026-18408 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-15741 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-14670 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-14680 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-14676 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-14671 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-16239 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-16238 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-15742 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-14677 (CVSS 3.1: 8.8)
- ๐ CVE-2026-14679 (CVSS 3.1: 8.2)
- ๐ CVE-2026-14669 (CVSS 3.1: 8.8)
- ๐ CVE-2026-14664 (CVSS 3.1: 8.8)
- ๐ CVE-2026-14662 (CVSS 3.1: 8.8)
- ๐ CVE-2026-19385 (CVSS 3.1: 8.8)
- ๐ CVE-2026-14668 (CVSS 3.1: 8.1)
๐ด [CRITICAL] seriousm4x/upsnap
1 CVE | CVSS 3.1: 9.8 | AAS 12.6
cpe:2.3:a:seriousm4x:upsnap:*:*:*:*:*:*:*:*
UpSnap, an open-source Wake-on-LAN web application, versions 4.4.1 through 5.3.5 is affected by a critical unauthenticated privilege escalation vulnerability (CVE-2026-49819, CVSS 9.8) with a functional exploit available. The init-superuser API endpoint lacks authentication and is only gated by a check on whether a superuser already exists, allowing an unauthenticated network-adjacent attacker to create a superuser account and take full control of the application on fresh or reset installations. Administrators running UpSnap should upgrade to version 5.4.0 immediately and review their instances for any unauthorized superuser accounts.
- ๐ด CVE-2026-49819 (CVSS 3.1: 9.8)
๐ด [CRITICAL] flowiseai/flowise
6 CVEs | CVSS 4.0: 9.4 | AAS 12.2
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*(< 3.1.3)
Flowise, an open-source AI workflow automation platform, versions 3.1.2 and earlier are affected by 6 vulnerabilities including multiple sandbox escape and remote code execution flaws, with a maximum CVSS of 9.4 and proof-of-concept exploit code available. Most critically, authenticated users can escape the JavaScript sandbox via the custom function API endpoint by abusing puppeteer to spawn arbitrary OS commands, often running as root in default Docker deployments. Organizations running Flowise should upgrade beyond version 3.1.2 immediately, restrict access to the custom function endpoint, and review deployments for signs of compromise, particularly any running the container as root.
- ๐ด CVE-2026-73483 (CVSS 4.0: 9.4)
- ๐ด CVE-2026-73601 (CVSS 4.0: 9.0)
- ๐ด CVE-2026-73602 (CVSS 4.0: 9.0)
- ๐ CVE-2026-73487 (CVSS 4.0: 9.0)
- ๐ CVE-2026-73486 (CVSS 4.0: 9.0)
- ๐ CVE-2026-73485 (CVSS 4.0: 9.0)
๐ด [CRITICAL] triggerdotdev/trigger.dev
1 CVE | CVSS 3.1: 9.9 | AAS 12.2
cpe:2.3:a:triggerdotdev:trigger.dev:*:*:*:*:*:*:*:*(< 4.5.6)
Trigger.dev, a platform for building and deploying managed AI agents and workflows, versions prior to 4.5.6 are affected by a critical cross-project authorization bypass vulnerability (CVE-2026-73656, CVSS 9.9) with proof-of-concept exploit code available. The background workers deployment API endpoint fails to scope deployment lookups by environment, allowing an authenticated user with a valid API key for one project to manipulate deployments belonging to other projects on the same instance. Organizations self-hosting or using Trigger.dev should upgrade to version 4.5.6 immediately and audit deployment logs for any unauthorized cross-project activity.
- ๐ด CVE-2026-73656 (CVSS 3.1: 9.9)
๐ด [CRITICAL] ibm/documentation_offline
2 CVEs | CVSS 3.1: 9.8 | AAS 12.1
cpe:2.3:a:ibm:documentation_offline:*:*:*:*:*:*:*:*(>= 1.0.0, < 1.4.2)
IBM Documentation Offline versions 1.0.0 through 1.4.1 is affected by 2 vulnerabilities, including at least one critical remote code execution flaw via improper control of file paths (CVSS 9.8) with functional exploits available. A remote attacker can exploit these issues to execute arbitrary code on affected systems without requiring complex preconditions. Organizations using IBM Documentation Offline should apply the patches referenced in IBM Support Node 7283484 immediately and review systems for any indicators of compromise.
- ๐ด CVE-2026-17482 (CVSS 3.1: 9.8)
- ๐ CVE-2026-17481 (CVSS 3.1: 8.8)
๐ด [CRITICAL] ibm/langflow_oss
1 CVE | CVSS 3.1: 9.1 | AAS 12.0
cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:*
IBM Langflow OSS versions 1.0.0 through 1.9.6 is affected by a critical authentication bypass vulnerability (CVE-2026-19297, CVSS 9.1) with functional exploits available. The platform fails to properly restrict excessive authentication attempts, allowing a remote attacker to brute-force credentials and gain unauthorized access to user accounts. Organizations running IBM Langflow OSS should upgrade beyond version 1.9.6 immediately, enforce account lockout policies, and review access logs for signs of brute-force activity.
- ๐ด CVE-2026-19297 (CVSS 3.1: 9.1)
๐ [HIGH] realmag777/active_products_tables_for_woocommerce
1 CVE | CVSS 3.1: 9.3 | AAS 11.8
cpe:2.3:a:realmag777:active_products_tables_for_woocommerce:*:*:*:*:*:*:*:*
Active Products Tables for WooCommerce, a WordPress plugin by realmag777, versions 1.1.1 and earlier is affected by a critical unauthenticated SQL injection vulnerability (CVE-2026-66436, CVSS 9.3) with proof-of-concept exploit code available. No authentication is required to exploit this flaw, meaning any internet-facing WooCommerce site running the vulnerable plugin is at risk of database extraction or manipulation. WordPress administrators should update the plugin immediately, audit database logs for suspicious queries, and consider deploying a web application firewall rule to block SQL injection attempts in the interim.
- ๐ CVE-2026-66436 (CVSS 3.1: 9.3)
๐ [HIGH] @fastify/busboy/@fastify/busboy
1 CVE | CVSS 3.1: 7.5 | AAS 11.6
cpe:2.3:a:fastify_busboy:fastify_busboy:*:*:*:*:*:*:*:*
@fastify/busboy, a widely used Node.js multipart form-data parser, versions 3.1.0 through 3.2.0 is affected by a denial-of-service vulnerability (CVE-2026-19484, CVSS 7.5) with a functional exploit available. A remote unauthenticated attacker can stall the Node.js event loop by sending a single multipart request with a specially crafted 252-byte boundary, causing the internal search algorithm to degrade into a CPU-bound infinite loop. Teams running Fastify-based applications or any Node.js service depending on @fastify/busboy should update beyond version 3.2.0 immediately, as a single malicious request is sufficient to render the service unresponsive.
- ๐ CVE-2026-19484 (CVSS 3.1: 7.5)
๐ [HIGH] svg/svgo
1 CVE | CVSS 3.1: 8.2 | AAS 11.5
cpe:2.3:a:svg:svgo:*:*:*:*:*:*:*:*
SVGO (SVG Optimizer), a widely used Node.js library and CLI tool for optimizing SVG files, versions 1.0.0 through 2.8.2, 3.3.3, and 4.0.1 is affected by a script sanitization bypass vulnerability (CVE-2026-73650, CVSS 8.2) with functional exploits available. The removeScripts plugin fails to strip namespaced or prefixed script elements such as svg:script and performs case-sensitive matching on JavaScript URIs, allowing executable content to persist in optimized SVGs and enabling cross-site scripting attacks against downstream applications. Teams processing untrusted SVG input through SVGO should upgrade to versions 2.8.3, 3.3.4, or 4.0.2 immediately and audit any previously optimized SVGs that originated from untrusted sources.
- ๐ CVE-2026-73650 (CVSS 3.1: 8.2)
๐ [HIGH] ibm/i
2 CVEs | CVSS 3.1: 8.6 | AAS 11.4
cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected by 2 vulnerabilities, including at least one out-of-bounds write flaw that allows a remote attacker to cause a denial of service (CVSS 8.6), with functional exploits available. These issues impact a broad range of supported IBM i releases, making them relevant to any organization running IBM midrange systems. Administrators should apply the fixes referenced in IBM Support Node 7283573 as soon as possible and monitor systems for unexpected service disruptions or anomalous activity.
- ๐ CVE-2026-17502 (CVSS 3.1: 8.6)
- ๐ CVE-2026-16815 (CVSS 3.1: 8.6)
๐ [HIGH] jandedobbeleer/oh-my-posh
1 CVE | CVSS 3.1: 7.8 | AAS 11.1
cpe:2.3:a:jandedobbeleer:oh-my-posh:*:*:*:*:*:*:*:*
Oh My Posh, a widely used cross-platform shell prompt renderer, versions prior to 29.35.1 is affected by a command injection vulnerability (CVE-2026-73505, CVSS 7.8) with functional exploits available. An attacker can craft a directory name containing a Go template expression that executes arbitrary OS commands as the current user whenever the prompt renders inside that directory, making it exploitable through cloned repositories or shared filesystems. Users should upgrade to version 29.35.1 immediately and exercise caution when navigating into untrusted directories, particularly from cloned or downloaded projects.
- ๐ CVE-2026-73505 (CVSS 3.1: 7.8)
๐ [HIGH] dayuanjiang/next-ai-draw-io
1 CVE | CVSS 4.0: 7.7 | AAS 11.1
cpe:2.3:a:dayuanjiang:next-ai-draw-io:*:*:*:*:*:*:*:*
Next AI Draw.io versions through 0.4.16 is affected by a server-side request forgery vulnerability (CVE-2026-72777, CVSS 7.7) with functional exploits available. The parse-url API endpoint performs hostname validation using string pattern checks without DNS resolution, allowing unauthenticated attackers to bypass restrictions and reach internal HTTP services, including cloud metadata endpoints, to exfiltrate sensitive data. Organizations running Next AI Draw.io should restrict network access to the application immediately, monitor for unexpected internal service requests, and watch for an upstream fix addressing DNS rebind-safe hostname validation.
- ๐ CVE-2026-72777 (CVSS 4.0: 7.7)
๐ [HIGH] rsyncproject/rsync
2 CVEs | CVSS 4.0: 9.2 | AAS 10.8
cpe:2.3:a:rsyncproject:rsync:*:*:*:*:*:*:*:*
rsync versions prior to 3.5.0 are affected by 2 vulnerabilities, including multiple command and argument injection flaws (CVSS 9.2) with proof-of-concept exploit code available. Attackers can inject shell metacharacters or newline characters through unsanitized inputs such as hostnames, the RSYNC_CONNECT_PROG environment variable, daemon hooks, and the rsync-ssl wrapper to execute arbitrary commands under the privileges of the rsync process. Given rsync’s ubiquitous use in backup, deployment, and file synchronization workflows across Linux and Unix systems, administrators should upgrade to version 3.5.0 immediately and audit any scripts or automation that pass untrusted input to rsync commands.
- ๐ CVE-2026-53790 (CVSS 4.0: 9.2)
- ๐ CVE-2026-70460 (CVSS 4.0: 9.2)
๐ [HIGH] nextauthjs/next-auth
1 CVE | CVSS 4.0: 9.1 | AAS 10.8
cpe:2.3:a:nextauthjs:next-auth:*:*:*:*:*:*:*:*
NextAuth.js (Auth.js) versions 5.0.0-beta.0 through 5.0.0-beta.31 are affected by an authentication bypass vulnerability (CVE-2026-73421, CVSS 9.1) that is confirmed exploitable. When Auth.js encounters a server configuration error, the auth() wrapper returns a truthy error object instead of null, causing common access control checks such as if (req.auth) to evaluate to true and grant unauthenticated users full access to protected routes, middleware, and server components. Teams using NextAuth.js v5 beta releases should upgrade to 5.0.0-beta.32 or later immediately and review access control logic to ensure it validates session contents rather than merely checking for object existence.
- ๐ CVE-2026-73421 (CVSS 4.0: 9.1)