14 vulnerabilities across 11 products scored HIGH or above on August 31, 2026.

  • ๐ŸŸ  HIGH: 14

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-65641 (veeam/one) โ€” F1: exploitable โ†’ functional, AAS: 10.4 โ†’ 12.4 (HIGH โ†’ CRITICAL). Originally in 2026-08-26 bulletin.

๐ŸŸ  [HIGH] zhenorzz/goploy

1 CVE | CVSS 3.1: 9.6 | AAS 11.4

  • cpe:2.3:a:zhenorzz:goploy:*:*:*:*:*:*:*:*

Goploy, an open-source automation deployment system by zhenorzz, is affected by one critical vulnerability (CVE-2026-53552, CVSS 9.6) involving broken access control across multiple API endpoints. The flaw allows a user with the manager role to manipulate projects outside their assigned namespace by supplying arbitrary project or file row IDs, because the backend fails to verify namespace ownership before acting on requests. A proof-of-concept exploit is publicly available. Organizations running Goploy version 1.17.5 or earlier should review the vendor advisory at the linked GitHub Security Advisory, apply any available patches or mitigations immediately, and audit project access logs for signs of unauthorized cross-namespace activity.

Vendor Advisory


๐ŸŸ  [HIGH] yacy/yacy_search_server

1 CVE | CVSS 4.0: 8.7 | AAS 10.8

  • cpe:2.3:a:yacy:yacy_search_server:*:*:*:*:*:*:*:*

YaCy Search Server through version 1.941 is affected by one high-severity vulnerability (CVE-2026-82880, CVSS 8.7) involving XML external entity injection in the SVG, FreeMind, and OpenSearch parsers used by the crawler. An attacker can publish specially crafted documents containing malicious DOCTYPE declarations that cause the YaCy crawler to read local files from the server and expose their contents in the publicly searchable index, making this an exploitable server-side file exfiltration issue. Organizations running YaCy instances should immediately restrict crawler exposure to untrusted content sources, monitor indexed data for signs of local file leakage, and watch the vendor’s GitHub repository for a patched release.

Vendor Advisory


๐ŸŸ  [HIGH] nodemailer/nodemailer

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

  • cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*

Nodemailer versions prior to 8.0.4 are affected by one high-severity vulnerability (CVE-2026-82854, CVSS 9.3) involving SMTP command injection through the unsanitized envelope.size parameter. When an application passes user-controllable data into the custom envelope object, an attacker can inject CRLF sequences to append arbitrary SMTP commands such as RCPT TO, silently adding attacker-controlled recipients to outgoing emails and enabling data exfiltration or phishing from trusted infrastructure. Development and operations teams using Nodemailer in any Node.js application that handles email should upgrade to version 8.0.4 or later immediately, and review application code to ensure no untrusted input reaches the envelope object without validation.

Vendor Advisory


๐ŸŸ  [HIGH] samanhappy/mcphub

2 CVEs | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:samanhappy:mcphub:*:*:*:*:*:*:*:*

MCPHub, a centralized management hub for MCP servers by samanhappy, is affected by two high-severity vulnerabilities (CVE-2026-79748 and CVE-2026-79744, max CVSS 9.9) including at least one that allows any authenticated user to achieve remote code execution by creating or updating server configurations that spawn arbitrary processes via the server management API endpoints without proper authorization or input validation. These flaws are exploitable and pose critical risk to any organization running MCPHub, as a low-privileged authenticated user can escalate to full server compromise. Teams running MCPHub should upgrade to version 0.12.15 or later immediately, restrict network access to the management API, and audit server configuration logs for any unauthorized or suspicious process entries.

Vendor Advisory


๐ŸŸ  [HIGH] tenda/ac18

1 CVE | CVSS 4.0: 9.3 | AAS 9.8

  • cpe:2.3:a:tenda:ac18:*:*:*:*:*:*:*:*

Tenda AC18 routers running firmware version 15.03.05.19 are affected by one high-severity vulnerability (CVE-2026-82695, CVSS 9.3) in which the telnet handler endpoint at /goform/telnet lacks authentication entirely, allowing any remote attacker to enable telnet access on the device without credentials. Exploit details have been publicly released, making this an immediate risk for any network with exposed Tenda AC18 devices. Administrators should check for firmware updates from Tenda, disable remote management access, ensure the device is not reachable from the internet, and consider network segmentation or device replacement if no patch is available.

Vendor Advisory


๐ŸŸ  [HIGH] ใ‚ฆใ‚งใƒ–ๅฑ‹ใฎใ•ใจใƒผใ•ใ‚“/throws_spam_away

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a::throws_spam_away:*:*:*:*:*:*:*:* (< 3.8.3)

Throws SPAM Away, a WordPress anti-spam plugin, versions 3.8.2 and earlier are affected by one high-severity vulnerability (CVE-2026-81763, CVSS 9.3) involving unauthenticated SQL injection, meaning no login is required for an attacker to exploit it against any WordPress site running the plugin. This flaw is considered exploitable and could allow attackers to extract, modify, or delete database contents, potentially compromising the entire WordPress installation. Site administrators using Throws SPAM Away should update to a patched version immediately or deactivate the plugin until a fix is available, and review database logs for any signs of unauthorized access.

Vendor Advisory


๐ŸŸ  [HIGH] passionate_programmer_peter/wp_data_access

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:passionate_programmer_peter:wp_data_access:*:*:*:*:*:*:*:* (< 5.5.82)

WP Data Access, a WordPress database management plugin, versions 5.5.81 and earlier are affected by one high-severity vulnerability (CVE-2026-81293, CVSS 9.3) involving unauthenticated SQL injection, allowing remote attackers to interact with the WordPress database without any login or privileges. This is an exploitable flaw that could lead to full database compromise, including extraction of user credentials, modification of site content, or complete site takeover. WordPress administrators running WP Data Access should upgrade beyond version 5.5.81 immediately or deactivate the plugin until a patch is applied, and should audit their database and access logs for indicators of exploitation.

Vendor Advisory


๐ŸŸ  [HIGH] red_hat/red_hat_enterprise_linux_6

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:redhat:red_hat_enterprise_linux_6:*:*:*:*:*:*:*:*

Red Hat Enterprise Linux 6 is affected by one high-severity vulnerability (CVE-2026-83596, CVSS 8.8) in WebKitGTK, where processing maliciously crafted web content can trigger memory corruption due to improper memory handling, potentially allowing remote code execution when a user visits a compromised or attacker-controlled website. This flaw is considered exploitable and impacts any RHEL 6 system running applications that rely on WebKitGTK for rendering web content, such as GNOME-based browsers and email clients. Administrators should apply the relevant Red Hat security advisory patches as soon as they are available, and note that RHEL 6 has reached end-of-life โ€” organizations still running it should prioritize migration to a supported release or ensure they have Extended Life Cycle Support for continued patch access.

Vendor Advisory


๐ŸŸ  [HIGH] studio-42/elfinder

1 CVE | CVSS 3.1: 8.6 | AAS 9.4

  • cpe:2.3:a:studio-42:elfinder:*:*:*:*:*:*:*:* (< 2.1.70)

elFinder, an open-source web-based file manager, versions prior to 2.1.70 are affected by one high-severity vulnerability (CVE-2026-81889, CVSS 8.6) involving a server-side request forgery bypass in the URL upload functionality. When PHP cURL is unavailable, the SSRF validation and the actual connection perform separate DNS resolutions, allowing an attacker to use DNS rebinding to pass the security check and then redirect the server’s request to internal network resources or cloud metadata endpoints. Administrators running elFinder should upgrade to version 2.1.70 immediately, ensure PHP cURL is enabled on their web servers to avoid the vulnerable fallback code path, and review network logs for any suspicious outbound connections originating from the file manager.

Vendor Advisory


๐ŸŸ  [HIGH] opensearch/opensearch

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:opensearch:opensearch:*:*:*:*:*:*:*:* (< 2.16.0)

OpenSearch is affected by one high-severity vulnerability (CVE-2026-83497, CVSS 8.7) in the SQL plugin’s cursor pagination component, where unrestricted deserialization of untrusted data allows any authenticated user with basic read or search permissions to achieve remote code execution by sending a crafted cursor parameter to the plugins/sql endpoint. The low barrier to exploitation makes this particularly dangerous in multi-tenant or shared OpenSearch environments where many users hold basic query access. Administrators should consult the AWS security bulletin immediately for patched versions, apply updates as soon as possible, and review access logs for unusual requests to the SQL plugin endpoint.

Vendor Advisory


๐ŸŸ  [HIGH] ellite/wallos

3 CVEs | CVSS 3.1: 8.2 | AAS 9.0

  • cpe:2.3:a:ellite:wallos:*:*:*:*:*:*:*:* (< 5.0.0)

Wallos, an open-source self-hosted personal subscription tracker, versions prior to 5.0.0 are affected by three high-severity vulnerabilities (CVE-2026-77348, CVE-2026-54600, CVE-2026-61638, max CVSS 8.2), including at least one involving an incomplete SSRF fix where the unauthenticated payments search endpoint was left unpatched after an earlier logo search endpoint was hardened, allowing attackers to proxy requests through the server via HTTP_PROXY environment variable manipulation. These flaws are considered exploitable and pose a risk to anyone self-hosting Wallos with network exposure, as unauthenticated attackers could reach internal services or exfiltrate data. Administrators should upgrade to Wallos version 5.0.0 or later immediately, restrict network access to the application, and review proxy-related environment variables and outbound connection logs for signs of exploitation.

Vendor Advisory