62 vulnerabilities across 15 products scored HIGH or above on August 19, 2026.

  • 🟠 HIGH: 62

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-17083 (ibm/i) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-08-12 bulletin.

🟠 [HIGH] ibm/aix

21 CVEs | CVSS 3.1: 9.9 | AAS 11.9

  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.2.5, <= 7.2.5.212)
  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.3.2, <= 7.3.2.5)
  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.3.3, <= 7.3.3.2)
  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.3.4, <= 7.3.4.1)
  • cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* (>= 4.1.0, < 4.1.0.50)

IBM AIX versions 7.2 and 7.3, along with IBM PowerVM VIOS 4.1, are affected by 21 vulnerabilities, including multiple critical issues with CVSS scores up to 9.9. The most severe flaw allows remote attackers to execute arbitrary code through improper validation of network-supplied pointers, and exploitation is considered feasible. Administrators running AIX or PowerVM VIOS in their environments should prioritize patching immediately by reviewing the vendor advisory at https://www.ibm.com/support/pages/node/7283858 and applying all available fixes.

Vendor Advisory


🟠 [HIGH] ibm/vios

14 CVEs | CVSS 3.1: 9.9 | AAS 11.9

  • cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* (>= 4.1.0, < 4.1.0.50)
  • cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* (>= 4.1.1.0, < 4.1.1.30)
  • cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* (>= 4.1.2.0, < 4.1.2.20)
  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.2.5, <= 7.2.5.212)
  • cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* (>= 7.3.2, <= 7.3.2.5)

IBM PowerVM Virtual I/O Server (VIOS) 4.1, along with IBM AIX 7.2 and 7.3, is affected by 14 vulnerabilities, including multiple critical flaws with CVSS scores up to 9.9. The most severe issue is a stack-based buffer overflow that could allow a remote attacker to execute arbitrary code, and exploitation is considered feasible. Organizations running VIOS in virtualized Power Systems environments should apply patches immediately by consulting the vendor advisory at https://www.ibm.com/support/pages/node/7283858.

Vendor Advisory


🟠 [HIGH] cisco/cisco_secure_workload

3 CVEs | CVSS 3.1: 10.0 | AAS 11.2

  • cpe:2.3:a:cisco:cisco_secure_workload:*:*:*:*:*:*:*:*

Cisco Secure Workload is affected by 3 vulnerabilities, including multiple improper authentication flaws, with CVSS scores reaching 10.0 β€” the maximum possible severity. These issues were discovered during an internal security review and could allow an attacker to bypass authentication controls on affected deployments. Organizations using Cisco Secure Workload should apply the hardening release immediately by following the guidance in the vendor advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP.

Vendor Advisory


🟠 [HIGH] termix-ssh/termix

3 CVEs | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:termix-ssh:termix:*:*:*:*:*:*:*:* (< 2.6.1)

Termix, a web-based server management platform with SSH terminal and tunneling capabilities, is affected by 3 vulnerabilities prior to version 2.3.2, including multiple command injection flaws with CVSS scores up to 9.8. An authenticated user can inject shell commands through tunnel host fields by escaping quoted patterns, leading to arbitrary command execution on the underlying server during tunnel operations. Administrators running Termix should upgrade to version 2.3.2 or later immediately, with the fix available at https://github.com/Termix-SSH/Termix/commit/52f4e51ae03b5b8d2608e1383e2ccf79d290132b.

Vendor Advisory


🟠 [HIGH] verbb/formie

1 CVE | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:verbb:formie:*:*:*:*:*:*:*:*

Formie, a popular form-building plugin for Craft CMS, is affected by a server-side template injection vulnerability (CVE-2026-52889) with a CVSS score of 9.8. An unauthenticated attacker can inject Twig template syntax through request-controlled inputs such as User Agent, Referer, or cookie values when a public form uses an affected Hidden field type, potentially leading to remote code execution. Sites running Formie prior to version 3.1.27 should upgrade immediately, with the fix available at https://github.com/verbb/formie/commit/d3b9d15290405e484e3b5c91c5d8fab93047f9b2.

Vendor Advisory


🟠 [HIGH] ffmpeg/ffmpeg

4 CVEs | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

FFmpeg is affected by 4 vulnerabilities, including multiple memory corruption flaws with CVSS scores up to 9.3. The most severe is a heap buffer overflow in the RIST protocol reader, where a remote sender can overflow a destination buffer by sending an oversized payload via the async:rist:// URL scheme, potentially enabling remote code execution. Any organization using FFmpeg for media processing, streaming, or transcoding should update to a build that includes commit 1c10bcc or later, referenced at https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602.

Vendor Advisory


🟠 [HIGH] netty/netty

2 CVEs | CVSS 4.0: 9.1 | AAS 10.7

  • cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* (< 4.1.137.Final)
  • cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* (>= 4.2.0, < 4.2.17.Final)

Netty, a widely used asynchronous network application framework for Java, is affected by 2 vulnerabilities with CVSS scores up to 9.1. The more severe flaw involves an incorrect offset check in the TLS ClientHello handler, which can cause SNI-based mutual TLS authentication to fall back to a default context, potentially allowing unauthenticated clients to bypass per-SNI certificate requirements. Organizations relying on Netty’s SNI-based mTLS enforcement should upgrade to version 4.1.137.Final or 4.2.17.Final, with the fix available at https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7.

Vendor Advisory


🟠 [HIGH] sgoudelis/ground-station

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:sgoudelis:ground-station:*:*:*:*:*:*:*:* (< 0.4.13)

Ground Station, a browser-based suite for satellite tracking, SDR reception, and telemetry decoding, is affected by an unauthenticated path traversal vulnerability (CVE-2026-53451) with a CVSS score of 9.8. An attacker can exploit the save-waterfall-snapshot Socket.IO command to write arbitrary attacker-controlled content to any location on the filesystem by manipulating the snapshot name parameter, potentially achieving remote code execution. Users running Ground Station prior to version 0.4.13 should upgrade immediately, with the fix available at https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d.

Vendor Advisory


🟠 [HIGH] wazuh/wazuh

4 CVEs | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* (>= 4.0.0, < 4.14.6)
  • cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* (>= 5.0.0-beta3)
  • cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* (>= 5.0.0-beta1, < 5.0.0-beta3)

Wazuh, a widely deployed open source security monitoring and threat detection platform, is affected by 4 vulnerabilities with CVSS scores up to 9.1, impacting versions 4.0.0 through 4.14.5 and 5.0.0-beta3. The most severe flaw allows a cluster peer holding the shared Fernet key to perform path traversal through crafted synchronization archives, writing arbitrary files outside the intended cluster directory and potentially compromising the Wazuh manager. Organizations running affected versions should upgrade to 4.14.6 or later immediately, with the fix available at https://github.com/wazuh/wazuh/commit/88fc89fdfb1bf37b9d826e9c281a3d22655733de.

Vendor Advisory


🟠 [HIGH] splunk/splunk

3 CVEs | CVSS 3.1: 9.4 | AAS 10.4

  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* (>= 9.4.0, < 9.4.14)
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* (>= 10.0.0, < 10.0.9)
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* (>= 10.2.0, < 10.2.6)
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* (>= 10.4.0, < 10.4.2)

Splunk Enterprise is affected by 3 vulnerabilities with CVSS scores up to 9.4, impacting versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The most critical flaw allows an unauthenticated attacker with an embedded report token to recover session material from search job dispatch archives, potentially gaining full access to the report owner’s data and performing administrative actions if the owner holds the admin role. Organizations running Splunk Enterprise should upgrade to a patched version immediately by reviewing the vendor advisory at https://advisory.splunk.com/advisories/SVD-2026-0801.

Vendor Advisory


🟠 [HIGH] red_hat/multicluster_engine_for_kubernetes

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:redhat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:*

Red Hat Multicluster Engine for Kubernetes is affected by an authentication and authorization bypass vulnerability (CVE-2026-66794) with a CVSS score of 9.3 in the cluster-proxy-addon component. An unauthenticated attacker with access to the user-facing route can manipulate URL path segments to proxy requests to arbitrary services across any managed cluster, enabling unauthorized access to otherwise protected internal services. Organizations using Multicluster Engine for Kubernetes should review the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-66794 and apply available patches immediately to prevent cross-cluster exploitation.

Vendor Advisory


🟠 [HIGH] cisco/cisco_crosswork_planning

1 CVE | CVSS 3.1: 10.0 | AAS 10.2

  • cpe:2.3:a:cisco:cisco_crosswork_planning:*:*:*:*:*:*:*:*

Cisco Crosswork Planning is affected by a maximum-severity vulnerability (CVE-2026-20358) with a CVSS score of 10.0, involving external control of the file system discovered during an internal security review. This flaw could allow an attacker to manipulate file system operations on affected deployments, potentially leading to full system compromise. Organizations using Cisco Crosswork Planning should apply the hardening release immediately by following the guidance at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh.

Vendor Advisory


🟠 [HIGH] electerm/electerm

1 CVE | CVSS 3.1: 8.8 | AAS 10.1

  • cpe:2.3:a:electerm:electerm:*:*:*:*:*:*:*:*

electerm, an open source terminal and SSH/SFTP client, is affected by a command injection vulnerability (CVE-2026-49255) with a CVSS score of 8.8 in versions prior to 3.11.11. A malicious SSH or SFTP server can craft filenames containing shell metacharacters that, when processed during file transfer or management operations, execute arbitrary operating system commands on the victim’s machine. Users of electerm should upgrade to version 3.11.11 or later immediately, with the fix available at https://github.com/electerm/electerm/commit/aa778818843b9c083bd711cd04644d102fcb5a42.

Vendor Advisory


🟠 [HIGH] libfuse/sshfs

1 CVE | CVSS 3.1: 9.3 | AAS 10.1

  • cpe:2.3:a:libfuse:sshfs:*:*:*:*:*:*:*:*

SSHFS, the FUSE-based network filesystem client for mounting remote directories over SSH, is affected by a symlink traversal vulnerability (CVE-2026-47187) with a CVSS score of 9.3 in versions prior to 3.7.6. A rogue SFTP server can return crafted absolute or relative symlink targets containing parent-directory components that bypass the transform_symlinks mitigation, allowing the server to redirect client file operations to arbitrary locations on the local filesystem. Users mounting untrusted or shared SSH servers with SSHFS should upgrade to version 3.7.6 or later immediately, with the fix available at https://github.com/libfuse/sshfs/commit/bcd132f17ccf1b8592a229df797c9b08883fec26.

Vendor Advisory


🟠 [HIGH] zephyrproject/zephyr

2 CVEs | CVSS 3.1: 8.8 | AAS 10.1

  • cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*

Zephyr RTOS is affected by 2 vulnerabilities with CVSS scores up to 8.8, including multiple stack buffer overflow flaws in the HL7800 cellular modem driver. The most severe issue allows a malicious cellular network to send crafted PDP-context response data that overflows a 256-byte stack buffer during address parsing, potentially enabling remote code execution on affected IoT and embedded devices. Teams deploying Zephyr-based firmware with HL7800 modem support should apply the patch available at https://github.com/zephyrproject-rtos/zephyr/commit/a1cbced64181bc0bdf95e1fd7118f2bb70cf679b and rebuild affected images immediately.

Vendor Advisory