18 vulnerabilities across 15 products scored HIGH or above on August 24, 2026.
- ๐ด CRITICAL: 1
- ๐ HIGH: 17
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-76904 (geotools/geotools) โ F1: exploitable โ functional, AAS: 10.6 โ 12.6 (HIGH โ CRITICAL). Originally in 2026-08-21 bulletin.
- [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ F1: exploitable โ functional, AAS: 10.2 โ 12.2 (HIGH โ CRITICAL). Originally in 2026-08-20 bulletin.
๐ด [CRITICAL] oauth2-proxy/oauth2-proxy
1 CVE | CVSS 4.0: 9.3 | AAS 12.5
cpe:2.3:a:oauth2-proxy:oauth2-proxy:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ด CVE-2026-76835 (CVSS 4.0: 9.3)
๐ [HIGH] phpipam/phpipam
1 CVE | CVSS 4.0: 9.3 | AAS 11.1
cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-67602 (CVSS 4.0: 9.3)
๐ [HIGH] canonical/lxd
1 CVE | CVSS 3.1: 9.9 | AAS 11.1
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-66897 (CVSS 3.1: 9.9)
๐ [HIGH] red_hat/red_hat_enterprise_linux_10
1 CVE | CVSS 3.1: 7.1 | AAS 10.9
cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-19685 (CVSS 3.1: 7.1)
๐ [HIGH] cozmoslabs/translatepress
1 CVE | CVSS 3.1: 9.8 | AAS 10.6
cpe:2.3:a:cozmoslabs:translatepress:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-78267 (CVSS 3.1: 9.8)
๐ [HIGH] exceljs/exceljs
2 CVEs | CVSS 4.0: 9.3 | AAS 10.2
cpe:2.3:a:exceljs:exceljs:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-78207 (CVSS 4.0: 9.3)
- ๐ CVE-2026-78208 (CVSS 4.0: 8.7)
๐ [HIGH] webkit/webkit
1 CVE | CVSS 3.1: 8.8 | AAS 10.1
cpe:2.3:a:webkit:webkit:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-78376 (CVSS 3.1: 8.8)
๐ [HIGH] redefiningtheweb/affiliate_pro_-affiliate_program_for_woocommerce&_wordpress
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:redefiningtheweb:affiliate_pro_-_affiliate_program_for_woocommerce_wordpress:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-32558 (CVSS 3.1: 9.8)
๐ [HIGH] typeorm/typeorm
1 CVE | CVSS 4.0: 8.7 | AAS 10.1
cpe:2.3:a:typeorm:typeorm:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-76848 (CVSS 4.0: 8.7)
๐ [HIGH] nektos/act
1 CVE | CVSS 4.0: 8.7 | AAS 10.1
cpe:2.3:a:nektos:act:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-76847 (CVSS 4.0: 8.7)
๐ [HIGH] cakephp/cakephp
1 CVE | CVSS 4.0: 9.2 | AAS 10.0
cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-77635 (CVSS 4.0: 9.2)
๐ [HIGH] rustdesk/rustdesk
1 CVE | CVSS 4.0: 8.5 | AAS 9.9
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-76840 (CVSS 4.0: 8.5)
๐ [HIGH] gohugoio/hugo
1 CVE | CVSS 4.0: 8.3 | AAS 9.7
cpe:2.3:a:gohugoio:hugo:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-10582 (CVSS 4.0: 8.3)
๐ [HIGH] fastify/fast-uri
3 CVEs | CVSS 3.1: 7.5 | AAS 9.6
cpe:2.3:a:fastify:fast-uri:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-75899 (CVSS 3.1: 7.5)
- ๐ CVE-2026-75975 (CVSS 3.1: 7.5)
- ๐ CVE-2026-76172 (CVSS 3.1: 7.5)
๐ [HIGH] a_cpt/acpt_(pro)_-_custom_post_types_plugin_for_wordpress
1 CVE | CVSS 3.1: 9.8 | AAS 9.6
cpe:2.3:a:a_cpt:acpt_pro_-_custom_post_types_plugin_for_wordpress:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-32563 (CVSS 3.1: 9.8)