18 vulnerabilities across 15 products scored HIGH or above on August 24, 2026.

  • ๐Ÿ”ด CRITICAL: 1
  • ๐ŸŸ  HIGH: 17

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76904 (geotools/geotools) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-21 bulletin.
  • [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-20 bulletin.

๐Ÿ”ด [CRITICAL] oauth2-proxy/oauth2-proxy

1 CVE | CVSS 4.0: 9.3 | AAS 12.5

  • cpe:2.3:a:oauth2-proxy:oauth2-proxy:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] phpipam/phpipam

1 CVE | CVSS 4.0: 9.3 | AAS 11.1

  • cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] canonical/lxd

1 CVE | CVSS 3.1: 9.9 | AAS 11.1

  • cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] red_hat/red_hat_enterprise_linux_10

1 CVE | CVSS 3.1: 7.1 | AAS 10.9

  • cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] cozmoslabs/translatepress

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:cozmoslabs:translatepress:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] exceljs/exceljs

2 CVEs | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:exceljs:exceljs:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] webkit/webkit

1 CVE | CVSS 3.1: 8.8 | AAS 10.1

  • cpe:2.3:a:webkit:webkit:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] redefiningtheweb/affiliate_pro_-affiliate_program_for_woocommerce&_wordpress

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:redefiningtheweb:affiliate_pro_-_affiliate_program_for_woocommerce_wordpress:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] typeorm/typeorm

1 CVE | CVSS 4.0: 8.7 | AAS 10.1

  • cpe:2.3:a:typeorm:typeorm:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] nektos/act

1 CVE | CVSS 4.0: 8.7 | AAS 10.1

  • cpe:2.3:a:nektos:act:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] cakephp/cakephp

1 CVE | CVSS 4.0: 9.2 | AAS 10.0

  • cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] rustdesk/rustdesk

1 CVE | CVSS 4.0: 8.5 | AAS 9.9

  • cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] gohugoio/hugo

1 CVE | CVSS 4.0: 8.3 | AAS 9.7

  • cpe:2.3:a:gohugoio:hugo:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] fastify/fast-uri

3 CVEs | CVSS 3.1: 7.5 | AAS 9.6

  • cpe:2.3:a:fastify:fast-uri:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] a_cpt/acpt_(pro)_-_custom_post_types_plugin_for_wordpress

1 CVE | CVSS 3.1: 9.8 | AAS 9.6

  • cpe:2.3:a:a_cpt:acpt_pro_-_custom_post_types_plugin_for_wordpress:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory