31 vulnerabilities across 15 products scored HIGH or above on August 18, 2026.
- π΄ CRITICAL: 7
- π HIGH: 24
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-17083 (ibm/i) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-12 bulletin.
π΄ [CRITICAL] oracle_corporation/oracle_weblogic_server
7 CVEs | CVSS 3.1: 9.9 | AAS 12.9
cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*(>= 12.2.1.4.0)cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*(>= 14.1.1.0.0)cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*(>= 14.1.2.0.0)cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*(>= 15.1.1.0.0)cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:*(>= 12.2.1.4.0, < 12.2.1.4.0)
Oracle WebLogic Server is affected by seven vulnerabilities disclosed in the August 2026 Critical Patch Update, including multiple critical-severity flaws. The most severe, carrying a CVSS score of 9.8, allows an unauthenticated attacker with network access via IIOP to fully compromise WebLogic Server without any user interaction. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Organizations running Oracle WebLogic Server in any capacity should prioritize applying the patches from Oracle’s August 2026 security advisory immediately, and as an interim measure consider restricting network access to IIOP endpoints.
- π΄ CVE-2026-60698 (CVSS 3.1: 9.8)
- π΄ CVE-2026-60672 (CVSS 3.1: 9.8)
- π΄ CVE-2026-60696 (CVSS 3.1: 9.8)
- π΄ CVE-2026-60977 (CVSS 3.1: 9.8)
- π΄ CVE-2026-60702 (CVSS 3.1: 9.9)
- π CVE-2026-60699 (CVSS 3.1: 8.6)
- π CVE-2026-60680 (CVSS 3.1: 8.1)
π΄ [CRITICAL] oracle_corporation/peoplesoft_enterprise_peopletools
3 CVEs | CVSS 3.1: 9.8 | AAS 12.9
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*:*(>= 8.61, < 8.64)
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected by three vulnerabilities, including at least one critical-severity flaw with a CVSS score of 9.8 that allows an unauthenticated attacker to achieve full system takeover via HTTP through the Business Interlink component. Organizations running PeopleSoft PeopleTools should treat this as a high-priority patching event, as the attack requires no credentials or user interaction. Apply the fixes from Oracle’s August 2026 Critical Patch Update immediately and review network exposure of PeopleSoft instances to limit unnecessary HTTP access.
- π΄ CVE-2026-60821 (CVSS 3.1: 9.8)
- π CVE-2026-60967 (CVSS 3.1: 8.8)
- π CVE-2026-60879 (CVSS 3.1: 8.8)
π΄ [CRITICAL] wpmudev/forminator_forms_β_contact_form,payment_form&_custom_form_builder
1 CVE | CVSS 3.1: 9.8 | AAS 12.6
cpe:2.3:a:wpmudev:forminator_forms_contact_form_payment_form_custom_form_builder:*:*:*:*:*:*:*:*
The WPMU DEV Forminator Forms plugin for WordPress versions through 1.56.1 contains a critical arbitrary file upload vulnerability with a CVSS score of 9.8, allowing unauthenticated attackers to upload and execute malicious files by bypassing the extension blocklist through crafted MIME type keys and forged form field values. Functional exploit techniques are available for this flaw, making active exploitation a near-term risk for any WordPress site running the plugin. Site administrators should update Forminator Forms immediately, and if an update is not yet available, consider temporarily disabling file upload fields or deactivating the plugin until a patch is applied.
- π΄ CVE-2026-15748 (CVSS 3.1: 9.8)
π [HIGH] netflix/lemur
2 CVEs | CVSS 3.1: 9.9 | AAS 11.7
cpe:2.3:a:netflix:lemur:*:*:*:*:*:*:*:*
Netflix Lemur, an open-source TLS certificate management tool, is affected by two high-severity vulnerabilities prior to version 1.9.2, including a server-side request forgery flaw with a CVSS score of 9.9 that allows authenticated users to manipulate the ACME authority URL and make backend requests to cloud metadata endpoints or internal services, potentially leaking host credentials. Proof-of-concept exploit code is publicly available, increasing the likelihood of real-world exploitation. Organizations running Lemur should upgrade to version 1.9.2 or later immediately, and review whether any cloud instance metadata or internal service credentials may have been exposed through the Lemur host’s network context.
- π CVE-2026-55166 (CVSS 3.1: 9.9)
- π CVE-2026-48508 (CVSS 3.1: 8.8)
π [HIGH] nvidia/triton_inference_server
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
NVIDIA Triton Inference Server for Linux contains a path traversal vulnerability with a CVSS score of 9.8 that could allow an attacker to cause denial of service, with the high CVSS rating suggesting potential for broader impact beyond availability disruption. This flaw is considered exploitable and requires no authentication, making it a significant risk for any organization exposing Triton Inference Server instances, particularly in AI and machine learning inference pipelines. Teams running Triton Inference Server should apply the vendor-provided fix immediately and restrict network access to the service to trusted sources while patching is underway.
- π CVE-2026-47627 (CVSS 3.1: 9.8)
π [HIGH] lxsmnsyc/seroval
1 CVE | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:lxsmnsyc:seroval:*:*:*:*:*:*:*:*
Seroval, a JavaScript serialization library used for complex value stringification, contains a critical deserialization vulnerability prior to version 1.5.3 with a CVSS score of 9.8 that allows attackers to craft malicious JSON input exploiting Promise control nodes in seroval.fromJSON(), potentially achieving remote code execution when downstream frameworks register server-side handlers with plugins enabled. This flaw is considered exploitable and is particularly dangerous for server-side JavaScript applications using seroval for untrusted input deserialization. Developers should upgrade to seroval 1.5.3 or later immediately, and audit any applications that pass untrusted data through seroval.fromJSON() for signs of unexpected server-side invocation.
- π CVE-2026-59940 (CVSS 3.1: 9.8)
π [HIGH] oracle_corporation/oracle_access_manager
2 CVEs | CVSS 3.1: 9.8 | AAS 10.9
cpe:2.3:a:oracle:oracle_access_manager:*:*:*:*:*:*:*:*(>= 12.2.1.4.0)cpe:2.3:a:oracle:oracle_access_manager:*:*:*:*:*:*:*:*(>= 14.1.2.1.0)
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected by two vulnerabilities, including at least one critical flaw with a CVSS score of 9.8 that allows an unauthenticated attacker to achieve full system takeover via SAML through the Agent infrastructure component with no user interaction required. Given Oracle Access Manager’s role as a centralized authentication and single sign-on gateway, compromise of this component could grant attackers broad access across the federated environment. Organizations should apply the patches from Oracle’s August 2026 Critical Patch Update as a top priority and review SAML endpoint exposure to minimize attack surface.
- π CVE-2026-70905 (CVSS 3.1: 9.8)
- π CVE-2026-60726 (CVSS 3.1: 8.8)
π [HIGH] atlassian/confluence_data_center
1 CVE | CVSS 4.0: 9.3 | AAS 10.9
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*(>= 7.1.1)
Atlassian Confluence Data Center and Server are affected by a critical stored cross-site scripting vulnerability that enables privilege escalation, impacting a wide range of versions from 7.1.1 through 10.2.0. The flaw allows an unauthenticated attacker to execute arbitrary HTML or JavaScript, and is considered exploitable, posing a serious risk to any organization relying on Confluence for internal collaboration and knowledge management. Administrators should consult the Atlassian security advisory immediately, apply the recommended patches or upgrade to a fixed version, and audit Confluence instances for signs of injected content.
- π CVE-2026-21580 (CVSS 4.0: 9.3)
π [HIGH] gohugoio/hugo
1 CVE | CVSS 4.0: 9.3 | AAS 10.7
cpe:2.3:a:gohugoio:hugo:*:*:*:*:*:*:*:*
Hugo version 0.162.0 contains a high-severity security sandbox escape vulnerability where the default addition of tailwindcss to the AllowChildProcess list allows malicious code in a site’s tailwind.config.js to break out of the Node.js permission model and access the file system beyond the project directory, potentially leading to arbitrary code execution during site builds. This flaw is considered exploitable and affects any Hugo deployment using TailwindCSS integration, particularly CI/CD pipelines and shared build environments where untrusted site content may be processed. Teams using Hugo with TailwindCSS should check for an updated release, and in the interim consider removing tailwindcss from the AllowChildProcess security configuration or auditing tailwind.config.js files for unexpected code.
- π CVE-2026-75926 (CVSS 4.0: 9.3)
π [HIGH] piotnet/piotnet_addons_for_elementor_pro
1 CVE | CVSS 3.1: 9.6 | AAS 10.7
cpe:2.3:a:piotnet:piotnet_addons_for_elementor_pro:*:*:*:*:*:*:*:*
Piotnet Addons For Elementor Pro, a WordPress plugin, contains a critical unauthenticated arbitrary file upload vulnerability in versions up to and including 7.1.67 with a CVSS score of 9.6, allowing attackers to upload malicious files to vulnerable sites without any authentication. This flaw is considered exploitable and poses an immediate risk of full site compromise, including webshell deployment and server takeover, for any WordPress site running the affected plugin. Site administrators should update to a patched version immediately or deactivate the plugin until a fix is available, and inspect web-accessible upload directories for any suspicious files.
- π CVE-2026-28192 (CVSS 3.1: 9.6)
π [HIGH] ohmyzsh/ohmyzsh
1 CVE | CVSS 3.1: 8.8 | AAS 10.6
cpe:2.3:a:ohmyzsh:ohmyzsh:*:*:*:*:*:*:*:*
Oh My Zsh’s dotenv plugin prior to the 2026-05-28 patch contains a command injection vulnerability with a CVSS score of 8.8, where a malicious .env file can execute arbitrary shell commands with the current user’s privileges when a developer changes into a directory containing it, particularly dangerous when the confirmation prompt is disabled or dismissed with a default Enter keystroke. This flaw is considered exploitable and poses a significant risk to developers and engineers who use Oh My Zsh with the dotenv plugin enabled, especially in environments where repositories or shared directories may contain untrusted .env files. Users should update Oh My Zsh immediately, review their ZSH_DOTENV_PROMPT setting, and audit any recently accessed directories for suspicious .env file contents.
- π CVE-2026-50187 (CVSS 3.1: 8.8)
π [HIGH] mybb/mybb
4 CVEs | CVSS 3.1: 9.8 | AAS 10.6
cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*
MyBB forum software versions 1.8.13 through 1.8.39 are affected by four vulnerabilities, including at least one critical flaw with a CVSS score of 9.8 that enables remote code execution through PHP code injection via improperly escaped database configuration values in the installer module. These vulnerabilities are considered exploitable and are particularly dangerous on any MyBB installation where the install directory has not been removed after setup, a common oversight. Administrators should upgrade to MyBB 1.8.40 immediately, verify that the install directory is deleted or inaccessible on all instances, and review server logs for any suspicious activity targeting the installer endpoint.
- π CVE-2026-45117 (CVSS 3.1: 9.8)
- π CVE-2026-45118 (CVSS 3.1: 9.3)
- π CVE-2026-45115 (CVSS 3.1: 8.7)
- π CVE-2026-45116 (CVSS 3.1: 8.7)
π [HIGH] oracle_corporation/oracle_identity_manager
4 CVEs | CVSS 3.1: 9.9 | AAS 10.4
cpe:2.3:a:oracle:oracle_identity_manager:*:*:*:*:*:*:*:*(>= 12.2.1.4.0)cpe:2.3:a:oracle:oracle_identity_manager:*:*:*:*:*:*:*:*(>= 14.1.2.1.0)
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected by four vulnerabilities, including multiple critical flaws with CVSS scores up to 9.9, the most severe of which allows an unauthenticated attacker to achieve full system takeover via HTTP through the OIM Legacy UI component. As a centralized identity and access management platform, compromise of Oracle Identity Manager could give attackers control over user provisioning and access rights across the enterprise. Organizations should apply the patches from Oracle’s August 2026 Critical Patch Update with the highest urgency and restrict network access to Identity Manager interfaces, particularly the Legacy UI, to trusted networks only.
- π CVE-2026-60721 (CVSS 3.1: 9.8)
- π CVE-2026-60727 (CVSS 3.1: 9.8)
- π CVE-2026-60720 (CVSS 3.1: 9.9)
- π CVE-2026-61066 (CVSS 3.1: 9.9)
π [HIGH] dragonflydb/dragonfly
1 CVE | CVSS 4.0: 8.8 | AAS 10.2
cpe:2.3:a:dragonflydb:dragonfly:*:*:*:*:*:*:*:*(< 1.40.0)
Dragonfly, an in-memory data store designed as a modern Redis alternative, contains a heap buffer overflow vulnerability prior to version 1.40.0 where integer overflow in CMS.INITBYDIM and CMS.INITBYPROB commands results in an undersized buffer allocation, allowing an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. This flaw is considered exploitable and affects any Dragonfly deployment exposed to untrusted clients, with potential impact ranging from denial of service to memory disclosure. Teams running Dragonfly should upgrade to version 1.40.0 immediately and ensure that instances are not directly accessible from untrusted networks without authentication or network-level access controls.
- π CVE-2026-62357 (CVSS 4.0: 8.8)
π [HIGH] frangoteam/fuxa
1 CVE | CVSS 4.0: 9.2 | AAS 10.0
cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:*
FUXA, a web-based SCADA/HMI process visualization platform, contains a critical authentication bypass vulnerability in versions 1.3.2 and earlier where a remote unauthenticated attacker can obtain a signed guest token via the heartbeat endpoint and use it to access the Node-RED editor and flow deployment API, potentially achieving arbitrary code execution on the underlying server. This flaw is considered exploitable and is especially concerning given FUXA’s role in industrial control and process visualization environments where unauthorized access could have physical-world consequences. Organizations running FUXA should apply the vendor patch immediately, disable the Node-RED integration if not required, and audit their instances for any unauthorized flow deployments or suspicious token activity.
- π CVE-2026-67443 (CVSS 4.0: 9.2)