1 vulnerability across 1 product scored HIGH or above on August 26, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76904 (geotools/geotools) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-08-21 bulletin.
  • [UPGRADED] CVE-2026-72843 (evershopcommerce/evershop) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.2 (HIGH โ†’ CRITICAL). Originally in 2026-08-20 bulletin.

๐ŸŸ  [HIGH] themefusion/avada_(fusion)_builder

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:themefusion:avada_fusion_builder:*:*:*:*:*:*:*:* (< 3.17)

ThemeFusion Avada (Fusion) Builder versions 3.16 and earlier, along with the Avada theme versions 7.16 and earlier, contain a critical unauthenticated arbitrary file write vulnerability (CVE-2026-18431, CVSS 9.8) that allows remote attackers to upload and execute malicious PHP files on the server by chaining authorization and input validation weaknesses across both components. Any WordPress site running the Avada theme with Fusion Builder active is at risk of full remote code execution without authentication.

Site administrators should update both the Avada theme and Fusion Builder plugin immediately to patched versions. If updates cannot be applied right away, consider temporarily deactivating the Fusion Builder plugin and auditing web-accessible directories for unexpected PHP files that may indicate prior exploitation.

Vendor Advisory