5 vulnerabilities across 4 products scored HIGH or above on August 25, 2026.

  • ๐ŸŸ  HIGH: 5

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-20 bulletin.

๐ŸŸ  [HIGH] zephyrproject/zephyr

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] nltk/nltk

2 CVEs | CVSS 4.0: 9.4 | AAS 10.3

  • cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] vrana/adminer

1 CVE | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:vrana:adminer:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory


๐ŸŸ  [HIGH] getgrav/grav

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*

Failed to authenticate: OAuth session expired and could not be refreshed

Vendor Advisory