8 vulnerabilities across 4 products scored HIGH or above on August 28, 2026.
- π HIGH: 8
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-65641 (veeam/one) β F1: exploitable β functional, AAS: 10.4 β 12.4 (HIGH β CRITICAL). Originally in 2026-08-26 bulletin.
- [UPGRADED] CVE-2026-76904 (geotools/geotools) β F1: exploitable β functional, AAS: 10.6 β 12.6 (HIGH β CRITICAL). Originally in 2026-08-21 bulletin.
π [HIGH] wazuh/wazuh
2 CVEs | CVSS 3.1: 9.1 | AAS 10.5
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*(>= 4.4.0, < 4.14.7)cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*(< 4.12.0)
Wazuh versions 4.4.0 through 4.14.6 are affected by 2 vulnerabilities, including at least one critical flaw (CVSS 9.1) that allows an attacker holding the cluster key to achieve arbitrary file write, overwrite, or deletion on worker nodes via the cluster synchronization mechanism, leading to remote code execution as root. Organizations running Wazuh as their XDR or SIEM platform should treat this as high priority, as exploitation of the cluster sync path traversal could result in full compromise of monitored infrastructure. Security teams should update to a patched version immediately and review the vendor advisory at the linked GitHub commit for remediation details.
- π CVE-2026-61800 (CVSS 3.1: 9.1)
- π CVE-2026-54083 (CVSS 3.1: 8.1)
π [HIGH] labring/fastgpt
1 CVE | CVSS 4.0: 9.3 | AAS 10.2
cpe:2.3:a:labring:fastgpt:*:*:*:*:*:*:*:*(< 4.15.2)
FastGPT versions prior to 4.15.2 are affected by a high-severity vulnerability (CVSS 9.3) in which the WeChat share-channel endpoints authorize requests using only the publicly known shareId, with no authentication or team-ownership verification, allowing an unauthenticated attacker to disconnect a victim team’s WeChat bot or hijack the channel entirely. Organizations using FastGPT’s WeChat integration to expose AI applications should treat this as urgent, since exploitation requires only knowledge of a shareId and no credentials. Teams should upgrade to FastGPT 4.15.2 or later immediately and review the vendor advisory at the linked GitHub commit for full remediation guidance.
- π CVE-2026-68929 (CVSS 4.0: 9.3)
π [HIGH] ceph/ceph
1 CVE | CVSS 3.1: 9.1 | AAS 9.9
cpe:2.3:a:ceph:ceph:*:*:*:*:*:*:*:*(>= 19.0.0, < 19.2.6)cpe:2.3:a:ceph:ceph:*:*:*:*:*:*:*:*(>= 20.0.0, < 20.2.4)
Ceph versions prior to 20.2.4 and 19.2.6 are affected by a high-severity vulnerability (CVSS 9.1) in which the Monitor subscription handler fails to enforce proper authorization on the configuration-key store, allowing any CephX user with minimal read-only monitor privileges to extract sensitive secrets including OSD LUKS disk-encryption passphrases and cephadm-managed cluster credentials via a single crafted MMonSubscribe message. Organizations running Ceph for distributed storage should treat this as high priority, as exploitation by a low-privileged authenticated user could expose encryption keys and enable full compromise of the storage cluster. Teams should upgrade to Ceph 20.2.4 or 19.2.6 immediately and review the vendor advisory at the linked GitHub commit for remediation details.
- π CVE-2026-50152 (CVSS 3.1: 9.1)
π [HIGH] watchguard/fireware_os
4 CVEs | CVSS 4.0: 9.3 | AAS 9.2
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
WatchGuard Fireware OS is affected by 4 vulnerabilities, including multiple high-severity flaws (max CVSS 9.3), with the most critical being a stack-based buffer overflow in the iked process that allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. Any organization with WatchGuard firewalls deployed at the network perimeter should treat this as urgent, as the affected IKE daemon is internet-facing by design and exploitation requires no authentication or user interaction. Administrators should apply the latest Fireware OS update immediately and review the vendor advisory at psirt.watchguard.com for patch versions and additional details on all four vulnerabilities.
- π CVE-2026-19318 (CVSS 4.0: 9.3)
- π CVE-2026-19315 (CVSS 4.0: 9.3)
- π CVE-2026-19313 (CVSS 4.0: 9.3)
- π CVE-2026-13086 (CVSS 4.0: 9.3)