1 vulnerability across 1 product scored HIGH or above on August 13, 2026.
- ๐ด CRITICAL: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-72886 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72882 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72901 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72737 (dokploy/dokploy) โ F1: exploitable โ functional, AAS: 9.7 โ 11.7 (HIGH โ HIGH). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-71558 (apache/fory) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) โ F1: theoretical โ poc, AAS: 9.1 โ 11.6 (HIGH โ HIGH). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-65507 (flavor/aiwu) โ F1: exploitable โ functional, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) โ F1: theoretical โ poc, AAS: 10.7 โ 13.2 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-34191 (apache/apr-util) โ F1: exploitable โ functional, AAS: 10.5 โ 13.7 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-28139 (ajax_search_lite/ajax_search_lite) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2025-15039 (wso2/api_control_plane) โ F1: theoretical โ itw, AAS: 9.9 โ 13.9 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-65583 (apache/cxf) โ F1: exploitable โ functional, AAS: 9.9 โ 11.9 (HIGH โ HIGH). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-68079 (apache/cxf) โ F1: theoretical โ poc, AAS: 9.6 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-08-06 bulletin.
๐ด [CRITICAL] seriousm4x/upsnap
1 CVE | CVSS 3.1: 9.8 | AAS 12.6
cpe:2.3:a:seriousm4x:upsnap:*:*:*:*:*:*:*:*(>= 4.4.1, < 5.3.6)
UpSnap by seriousm4x, an open-source Wake-on-LAN web application, is affected by one critical vulnerability (CVE-2026-49819, CVSS 9.8). The flaw is a missing-authentication issue in the superuser initialization endpoint that allows an unauthenticated attacker to create a privileged administrator account on any instance where no superuser has yet been configured, such as fresh installations. A functional exploit is available, increasing the urgency for remediation.
Security teams running UpSnap versions 4.4.1 through 5.3.5 should upgrade to version 5.4.0 immediately. Until patching is complete, restrict network access to the UpSnap management interface to trusted hosts only, as the vulnerable endpoint requires no authentication to exploit.
- ๐ด CVE-2026-49819 (CVSS 3.1: 9.8)