27 vulnerabilities across 15 products scored HIGH or above on August 25, 2026.

  • ๐ŸŸ  HIGH: 27

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76904 (geotools/geotools) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-21 bulletin.
  • [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-20 bulletin.

๐ŸŸ  [HIGH] adobe/adobe_campaign_classic

3 CVEs | CVSS 3.1: 10.0 | AAS 11.7

  • cpe:2.3:a:adobe:adobe_campaign_classic:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] zephyrproject/zephyr

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] chainlit/chainlit

1 CVE | CVSS 3.1: 9.8 | AAS 10.8

  • cpe:2.3:a:chainlit:chainlit:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] cbcoutinho/nextcloud-mcp-server

1 CVE | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:cbcoutinho:nextcloud-mcp-server:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] nltk/nltk

6 CVEs | CVSS 4.0: 9.4 | AAS 10.3

  • cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] eosphoros-ai/db-gpt

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:eosphoros-ai:db-gpt:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] klbtheme/total_donations

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:klbtheme:total_donations:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] miniorange.com/saml_sso_for_joomla_extension_for_joomla

1 CVE | CVSS 4.0: 10.0 | AAS 9.9

  • cpe:2.3:a:miniorange.com:saml_sso_for_joomla_extension_for_joomla:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] vrana/adminer

1 CVE | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:vrana:adminer:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] sparklemotion/nokogiri

4 CVEs | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:sparklemotion:nokogiri:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] alluxio/alluxio

1 CVE | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:alluxio:alluxio:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] mervinpraison/praisonai

1 CVE | CVSS 3.1: 9.1 | AAS 9.7

  • cpe:2.3:a:mervinpraison:praisonai:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] servmask/all-in-one_wp_migration_and_backup

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:servmask:all-in-one_wp_migration_and_backup:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] nvidia/openshell

3 CVEs | CVSS 3.1: 9.9 | AAS 9.6

  • cpe:2.3:a:nvidia:openshell:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] nvidia/nemoclaw

1 CVE | CVSS 3.1: 8.1 | AAS 9.4

  • cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory