27 vulnerabilities across 15 products scored HIGH or above on August 25, 2026.
- ๐ HIGH: 27
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-76904 (geotools/geotools) โ F1: exploitable โ functional, AAS: 10.6 โ 12.6 (HIGH โ CRITICAL). Originally in 2026-08-21 bulletin.
- [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ F1: exploitable โ functional, AAS: 10.2 โ 12.2 (HIGH โ CRITICAL). Originally in 2026-08-20 bulletin.
๐ [HIGH] adobe/adobe_campaign_classic
3 CVEs | CVSS 3.1: 10.0 | AAS 11.7
cpe:2.3:a:adobe:adobe_campaign_classic:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-76193 (CVSS 3.1: 10.0)
- ๐ CVE-2026-76195 (CVSS 3.1: 10.0)
- ๐ CVE-2026-76197 (CVSS 3.1: 10.0)
๐ [HIGH] zephyrproject/zephyr
1 CVE | CVSS 3.1: 9.8 | AAS 11.1
cpe:2.3:a:zephyrproject:zephyr:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-13214 (CVSS 3.1: 9.8)
๐ [HIGH] chainlit/chainlit
1 CVE | CVSS 3.1: 9.8 | AAS 10.8
cpe:2.3:a:chainlit:chainlit:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-45018 (CVSS 3.1: 9.8)
๐ [HIGH] cbcoutinho/nextcloud-mcp-server
1 CVE | CVSS 3.1: 9.1 | AAS 10.5
cpe:2.3:a:cbcoutinho:nextcloud-mcp-server:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-55640 (CVSS 3.1: 9.1)
๐ [HIGH] nltk/nltk
6 CVEs | CVSS 4.0: 9.4 | AAS 10.3
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-78683 (CVSS 4.0: 9.4)
- ๐ CVE-2026-79675 (CVSS 4.0: 9.3)
- ๐ CVE-2026-79657 (CVSS 4.0: 9.3)
- ๐ CVE-2026-79674 (CVSS 4.0: 8.8)
- ๐ CVE-2026-78682 (CVSS 4.0: 8.7)
- ๐ CVE-2026-79676 (CVSS 4.0: 8.2)
๐ [HIGH] eosphoros-ai/db-gpt
1 CVE | CVSS 4.0: 9.3 | AAS 10.2
cpe:2.3:a:eosphoros-ai:db-gpt:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-80104 (CVSS 4.0: 9.3)
๐ [HIGH] klbtheme/total_donations
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:klbtheme:total_donations:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-78570 (CVSS 3.1: 9.8)
๐ [HIGH] miniorange.com/saml_sso_for_joomla_extension_for_joomla
1 CVE | CVSS 4.0: 10.0 | AAS 9.9
cpe:2.3:a:miniorange.com:saml_sso_for_joomla_extension_for_joomla:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-77998 (CVSS 4.0: 10.0)
๐ [HIGH] vrana/adminer
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:vrana:adminer:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-56705 (CVSS 4.0: 9.3)
๐ [HIGH] sparklemotion/nokogiri
4 CVEs | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:sparklemotion:nokogiri:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2025-71407 (CVSS 4.0: 9.3)
- ๐ CVE-2026-79770 (CVSS 4.0: 8.7)
- ๐ CVE-2025-71406 (CVSS 4.0: 8.7)
- ๐ CVE-2026-79769 (CVSS 4.0: 8.7)
๐ [HIGH] alluxio/alluxio
1 CVE | CVSS 4.0: 9.3 | AAS 9.7
cpe:2.3:a:alluxio:alluxio:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-79787 (CVSS 4.0: 9.3)
๐ [HIGH] mervinpraison/praisonai
1 CVE | CVSS 3.1: 9.1 | AAS 9.7
cpe:2.3:a:mervinpraison:praisonai:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-55536 (CVSS 3.1: 9.1)
๐ [HIGH] servmask/all-in-one_wp_migration_and_backup
1 CVE | CVSS 3.1: 8.8 | AAS 9.6
cpe:2.3:a:servmask:all-in-one_wp_migration_and_backup:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-19949 (CVSS 3.1: 8.8)
๐ [HIGH] nvidia/openshell
3 CVEs | CVSS 3.1: 9.9 | AAS 9.6
cpe:2.3:a:nvidia:openshell:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-65091 (CVSS 3.1: 8.8)
- ๐ CVE-2026-65083 (CVSS 3.1: 9.9)
- ๐ CVE-2026-65093 (CVSS 3.1: 9.9)
๐ [HIGH] nvidia/nemoclaw
1 CVE | CVSS 3.1: 8.1 | AAS 9.4
cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*
Failed to authenticate: OAuth session expired and could not be refreshed
- ๐ CVE-2026-65105 (CVSS 3.1: 8.1)