21 vulnerabilities across 15 products scored HIGH or above on August 28, 2026.

  • πŸ”΄ CRITICAL: 3
  • 🟠 HIGH: 18

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-65641 (veeam/one) β€” F1: exploitable β†’ functional, AAS: 10.4 β†’ 12.4 (HIGH β†’ CRITICAL). Originally in 2026-08-26 bulletin.
  • [UPGRADED] CVE-2026-76904 (geotools/geotools) β€” F1: exploitable β†’ functional, AAS: 10.6 β†’ 12.6 (HIGH β†’ CRITICAL). Originally in 2026-08-21 bulletin.

πŸ”΄ [CRITICAL] liquid_web_/_stellarwp/givewp

1 CVE | CVSS 3.1: 10.0 | AAS 13.2

  • cpe:2.3:a:liquid_web_stellarwp:givewp:*:*:*:*:*:*:*:*

GiveWP, the popular WordPress donation plugin by Liquid Web / StellarWP, is affected by a critical unauthenticated PHP object injection vulnerability (CVE-2026-82222, CVSS 10.0) in all versions through 4.16.7.1. The flaw stems from deserialization of untrusted data and can be exploited by unauthenticated attackers to achieve remote code execution; a functional exploit is publicly available, making active exploitation highly likely. Organizations running GiveWP should update immediately to a patched release and review their environments for signs of compromise, consulting the vendor advisory at Patchstack for additional guidance.

Vendor Advisory


πŸ”΄ [CRITICAL] klever-io/klever-go

2 CVEs | CVSS 3.1: 9.6 | AAS 12.7

  • cpe:2.3:a:klever-io:klever-go:*:*:*:*:*:*:*:*

Klever-Go, the Go implementation of the Klever blockchain protocol, is affected by two critical vulnerabilities (CVE-2026-54754, CVE-2026-54755, max CVSS 9.6) in versions prior to 1.7.19, including multiple flaws in marketplace settlement logic that allow an asset owner to manipulate royalty and referral percentages after listing to drain funds from buyers during purchase execution. These vulnerabilities are confirmed exploited in the wild, meaning active abuse on-chain is occurring or has occurred. Node operators and anyone running Klever-Go infrastructure should upgrade to version 1.7.19 or later immediately and review recent marketplace transactions for anomalous royalty or referral payouts.

Vendor Advisory


πŸ”΄ [CRITICAL] kubeflow/pipelines

1 CVE | CVSS 3.1: 10.0 | AAS 12.6

  • cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:* (< 2.17.0)

Kubeflow Pipelines, the widely used ML workflow orchestration platform, contains a critical unauthenticated server-side request forgery vulnerability (CVE-2026-54745, CVSS 10.0) in versions prior to 2.17.0, where the frontend proxy route accepts arbitrary attacker-controlled URLs without allowlist filtering, enabling access to internal services, cloud metadata endpoints, and other network-adjacent resources. The flaw requires no authentication and is readily exploitable in any exposed Kubeflow Pipelines deployment. Organizations running Kubeflow Pipelines should upgrade to version 2.17.0 immediately and audit network logs for unexpected outbound requests originating from the frontend proxy.

Vendor Advisory


🟠 [HIGH] ibm/langflow_oss

2 CVEs | CVSS 3.1: 9.9 | AAS 11.6

  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0, < 1.11.2)

IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected by two high-severity vulnerabilities (CVE-2026-19295, CVE-2026-19286, max CVSS 9.9), including multiple flaws that allow an authenticated user to escalate privileges and execute arbitrary operating system commands under the server process identity by crafting malicious flow definitions, bypassing the custom component policy control. Proof-of-concept exploit code is available, increasing the likelihood of near-term exploitation. Organizations running Langflow OSS should apply the patches referenced in IBM’s security advisory immediately, restrict access to the flow editor to trusted users, and review server logs for signs of unauthorized command execution.

Vendor Advisory


🟠 [HIGH] portkey-ai/gateway

1 CVE | CVSS 4.0: 8.7 | AAS 11.3

  • cpe:2.3:a:portkey-ai:gateway:*:*:*:*:*:*:*:*

Portkey AI Gateway through version 1.15.2 contains a high-severity server-side request forgery vulnerability (CVE-2026-82270, CVSS 8.7) in the proxy route, where missing request validation allows an attacker to set the x-portkey-custom-host header to internal addresses, forwarding requests along with Authorization headers to reach internal services and exfiltrate LLM provider API keys. The flaw is exploitable without significant complexity and poses a direct risk of credential theft and lateral network access in any exposed deployment. Organizations using Portkey AI Gateway should upgrade past version 1.15.2, rotate any potentially exposed provider API keys, and restrict network-level access to the gateway’s proxy endpoint.

Vendor Advisory


🟠 [HIGH] pimcore/pimcore

2 CVEs | CVSS 3.1: 9.9 | AAS 11.1

  • cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*

Pimcore, the open source data and experience management platform, is affected by two high-severity vulnerabilities (CVE-2026-55634, CVE-2026-55220, max CVSS 9.9) in versions prior to 11.5.19, 12.3.10, and 2026.1.6, including multiple flaws in the class-definition import endpoint that allow an authenticated user to inject arbitrary code into generated PHP class files and SQL statements through unsanitized field names, leading to remote code execution and database compromise. These vulnerabilities are exploitable by any user with access to the Pimcore admin panel’s data modeling features. Administrators should upgrade to versions 11.5.19, 12.3.10, or 2026.1.6 immediately and audit recent class-definition imports for unexpected or malicious field names.

Vendor Advisory


🟠 [HIGH] jfrog/artifactory

1 CVE | CVSS 3.1: 9.8 | AAS 10.8

  • cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:* (< 7.90.6)

JFrog Artifactory contains a high-severity authentication weakness (CVE-2026-82329, CVSS 9.8) that, under default configuration, allows an unauthenticated attacker with network access to obtain full administrative privileges over the instance. Given Artifactory’s central role in software supply chains as a binary repository manager, compromise could enable tampering with build artifacts, injection of malicious packages, or exfiltration of proprietary code and credentials. Organizations running self-managed Artifactory instances should consult the vendor’s release documentation immediately for patched versions, verify that no unauthorized administrative accounts have been created, and restrict network access to the Artifactory management interface.

Vendor Advisory


🟠 [HIGH] wazuh/wazuh

2 CVEs | CVSS 3.1: 9.1 | AAS 10.5

  • cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*

Wazuh, the open source XDR and SIEM platform, is affected by two high-severity vulnerabilities (CVE-2026-61800, CVE-2026-54083, max CVSS 9.1) in versions 4.4.0 through 4.14.6, including multiple flaws in cluster file synchronization that allow an attacker holding the cluster key to write, overwrite, or delete arbitrary files under the Wazuh installation directory on worker nodes, leading to remote code execution as root. The irony of a security monitoring platform being exploitable for full system compromise makes prompt remediation especially critical, as these deployments typically hold privileged access across the entire monitored environment. Organizations should upgrade past version 4.14.6 immediately, rotate cluster keys, and audit worker nodes for unauthorized file modifications or unexpected processes running under the Wazuh service account.

Vendor Advisory


🟠 [HIGH] argoproj/argo-rollouts

1 CVE | CVSS 4.0: 9.3 | AAS 10.4

  • cpe:2.3:a:argoproj:argo-rollouts:*:*:*:*:*:*:*:*

Argo Rollouts dashboard through version 1.10.0 contains a high-severity vulnerability (CVE-2026-82277, CVSS 9.3) where the dashboard binds to all network interfaces and exposes mutating deployment operations such as promote, abort, restart, undo, and image changes without any authentication, authorization, or CSRF protection, allowing any attacker on the same network to manipulate rollouts across all namespaces accessible to the operator’s kubeconfig. This directly threatens production deployment integrity in Kubernetes environments, enabling unauthorized code deployments, service disruptions, or rollback of security patches. Organizations using Argo Rollouts should upgrade past version 1.10.0, ensure the dashboard is not exposed beyond localhost, and enforce network policies restricting access to the dashboard port.

Vendor Advisory


🟠 [HIGH] labring/fastgpt

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:labring:fastgpt:*:*:*:*:*:*:*:*

FastGPT, the open source LLM platform by Labring, contains a high-severity authorization bypass vulnerability (CVE-2026-68929, CVSS 9.3) in versions prior to 4.15.2, where WeChat share-channel endpoints rely solely on the public shareId for authorization without any authenticated identity or team-ownership verification, allowing an unauthenticated attacker to disconnect a victim team’s WeChat bot or hijack the channel to their own bot. Any organization exposing FastGPT’s WeChat integration is at risk of service disruption and channel takeover if their shareId is known or guessable. Teams should upgrade to version 4.15.2 or later immediately and review WeChat channel configurations for unauthorized modifications.

Vendor Advisory


🟠 [HIGH] redpanda-data/redpanda

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:redpanda-data:redpanda:*:*:*:*:*:*:*:*

Redpanda, the high-performance streaming data platform, through version 26.2.2 contains a high-severity vulnerability (CVE-2026-82266, CVSS 9.3) where the Admin API binds to all interfaces on port 9644 with authentication disabled by default, granting unauthenticated remote attackers full superuser access to create and delete broker accounts, modify cluster configuration, and disrupt partition replication. Any network-reachable Redpanda deployment running default settings is immediately exploitable with no credentials required. Organizations should upgrade past version 26.2.2, explicitly set admin_api_require_auth to true, restrict network access to port 9644 via firewall rules, and audit broker accounts and cluster configurations for unauthorized changes.

Vendor Advisory


🟠 [HIGH] yamcs/yamcs

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:yamcs:yamcs:*:*:*:*:*:*:*:*

Yamcs, the open source mission control framework, contains a high-severity YAML injection vulnerability (CVE-2026-55559, CVSS 9.8) in versions prior to 5.12.8 and 5.13.2, where unsanitized template arguments passed through the instance creation and update API endpoints allow an attacker to inject arbitrary YAML configuration, including malicious service entries that achieve remote code execution via the built-in ProcessRunner class. Deployments without authentication configured on the API are directly exploitable by any network-reachable attacker, posing particular risk given Yamcs’s use in satellite and spacecraft mission operations. Organizations should upgrade to version 5.12.8 or 5.13.2 immediately, ensure API authentication is enforced via security.yaml, and review instance configurations for any unauthorized service entries.

Vendor Advisory


🟠 [HIGH] ceph/ceph

1 CVE | CVSS 3.1: 9.1 | AAS 10.0

  • cpe:2.3:a:ceph:ceph:*:*:*:*:*:*:*:*

Ceph, the widely deployed open source distributed storage platform, contains a high-severity authorization bypass vulnerability (CVE-2026-50152, CVSS 9.1) in versions prior to 20.2.4 and 19.2.6, where the Monitor subscription handler fails to enforce proper access controls on the configuration-key store, allowing any CephX user with minimal read-only monitor capabilities to extract the entire store containing sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, SSH keys and other privileged credentials. Exploitation requires only a single crafted message from any authenticated Ceph client, making any compromised or low-privilege service account a path to full cluster and data compromise. Organizations should upgrade to Ceph 20.2.4 or 19.2.6 immediately, rotate all secrets stored in the config-key store including disk-encryption passphrases and SSH keys, and audit CephX capability grants for overly broad access.

Vendor Advisory


🟠 [HIGH] phpsysinfo/phpsysinfo

1 CVE | CVSS 3.1: 7.5 | AAS 9.8

  • cpe:2.3:a:phpsysinfo:phpsysinfo:*:*:*:*:*:*:*:*

phpSysInfo, a PHP-based system information dashboard, contains a high-severity access control bypass vulnerability (CVE-2026-55584, CVSS 7.5) in versions prior to 3.4.6, where the IP-based allowlist trusts attacker-controlled HTTP headers such as X-Forwarded-For and Client-IP before the actual remote address, allowing any unauthenticated remote attacker to spoof a trusted IP and access detailed system information including hostname, kernel version, CPU, memory, filesystem, and network interface data. Proof-of-concept exploit code is available, and the disclosed system details provide valuable reconnaissance for further attacks against the host. Organizations running phpSysInfo should upgrade to version 3.4.6 immediately and consider restricting access to the dashboard at the network or web server level rather than relying solely on application-layer IP checks.

Vendor Advisory


🟠 [HIGH] sveltejs/kit

3 CVEs | CVSS 4.0: 8.7 | AAS 9.6

  • cpe:2.3:a:sveltejs:kit:*:*:*:*:*:*:*:*

SvelteKit, the popular web application framework, is affected by three high-severity vulnerabilities (CVE-2026-82260, CVE-2026-82261, CVE-2026-82259, max CVSS 8.7) in versions 2.49.0 through 2.52.1 when the experimental remote functions feature is enabled, including multiple flaws in remote form deserialization that allow an attacker to crash the server process through memory exhaustion via malformed form data. These vulnerabilities are exploitable by any unauthenticated user capable of submitting form requests to an affected application. Teams using SvelteKit with experimental.remoteFunctions enabled should upgrade to version 2.52.2 immediately or disable the experimental remote functions feature until the update can be applied.

Vendor Advisory