25 vulnerabilities across 12 products scored HIGH or above on September 01, 2026.
- π HIGH: 25
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-65641 (veeam/one) β F1: exploitable β functional, AAS: 10.4 β 12.4 (HIGH β CRITICAL). Originally in 2026-08-26 bulletin.
π [HIGH] predis/predis
1 CVE | CVSS 3.1: 9.8 | AAS 11.4
cpe:2.3:a:predis:predis:*:*:*:*:*:*:*:*(>= 3.0.0-RC1, < 3.3.0)
Predis, a popular Redis and Valkey client library for PHP, is affected by one critical-severity vulnerability (CVE-2026-84372, CVSS 9.8). Versions 3.0.0-RC1 through 3.2.x contain a CRLF injection flaw in pipeline handling for aggregate cluster and replication connections, where attacker-controlled keys or values containing CRLF sequences can be interpreted as additional Redis commands due to improper parsing of serialized RESP buffers. This effectively allows command injection against the Redis backend and is considered exploitable. Any organization running Predis 3.0.0-RC1 or later in production should upgrade to version 3.3.0 immediately and review the vendor advisory at the linked GitHub commit for additional remediation details.
- π CVE-2026-84372 (CVSS 3.1: 9.8)
π [HIGH] vercel/next.js
1 CVE | CVSS 3.1: 9.0 | AAS 10.6
cpe:2.3:a:vercel:next.js:*:*:*:*:*:*:*:*(>= 13.4.0, < 15.5.24)cpe:2.3:a:vercel:next.js:*:*:*:*:*:*:*:*(>= 16.0.0, < 16.3.3)
Next.js, Vercel’s widely used React framework, is affected by one high-severity vulnerability (CVE-2026-75604, CVSS 9.0) impacting versions 13.4.0 through 15.5.23 and 16.x through 16.3.2. The flaw stems from insufficient backslash escaping in route segments when constructing incremental-cache file paths, allowing a remote attacker to supply crafted requests that manipulate cache paths on Windows-hosted servers running Pages Router or App Router without Cache Components. A proof-of-concept exploit is publicly available, so organizations hosting Next.js applications on Windows should upgrade to version 15.5.24 or 16.3.3 immediately and consult the vendor advisory for full remediation guidance.
- π CVE-2026-75604 (CVSS 3.1: 9.0)
π [HIGH] wwbn/avideo
4 CVEs | CVSS 4.0: 9.3 | AAS 10.5
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*(< 29.1)
WWBN AVideo, an open-source video streaming platform, is affected by four high-severity vulnerabilities (including CVE-2026-84479 and CVE-2026-84480, max CVSS 9.3). The flaws include authentication bypasses where login-time security controls such as two-factor authentication and brute-force captcha protections can be circumvented simply by spoofing a hardcoded User-Agent string, with no IP verification or shared secret required. Organizations running AVideo version e01e41ecc or earlier should treat these issues as exploitable, monitor the vendor advisory for a patched release, and consider restricting public access to AVideo login endpoints until a fix is available.
- π CVE-2026-84479 (CVSS 4.0: 9.3)
- π CVE-2026-84480 (CVSS 4.0: 9.3)
- π CVE-2026-84476 (CVSS 4.0: 8.7)
- π CVE-2026-84208 (CVSS 4.0: 8.7)
π [HIGH] erlang/otp
11 CVEs | CVSS 4.0: 8.7 | AAS 10.4
cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*
Erlang/OTP is affected by eleven vulnerabilities (including CVE-2026-73276 and CVE-2026-73812, max CVSS 8.7), with multiple issues considered exploitable. The flaws span the inets HTTP stack and other OTP components, with the lead vulnerability enabling HTTP request smuggling due to overly permissive parsing that accepts malformed inputs instead of rejecting them, affecting OTP versions from 22.2 through 27.3.4.16, 28.0 through 28.5.0.5, and 29.0 through 29.0.5. Any organization running Erlang-based infrastructure, including systems built on RabbitMQ, CouchDB, or other BEAM-based platforms, should upgrade to OTP 27.3.4.17, 28.5.0.6, or 29.0.6 immediately and review the vendor advisory for the full scope of affected components.
- π CVE-2026-73276 (CVSS 4.0: 8.3)
- π CVE-2026-73812 (CVSS 4.0: 8.3)
- π CVE-2026-66357 (CVSS 4.0: 8.3)
- π CVE-2026-55951 (CVSS 4.0: 8.2)
- π CVE-2026-75538 (CVSS 4.0: 8.2)
- π CVE-2026-74835 (CVSS 4.0: 8.7)
- π CVE-2026-70399 (CVSS 4.0: 8.7)
- π CVE-2026-69664 (CVSS 4.0: 8.7)
- π CVE-2026-71380 (CVSS 4.0: 8.7)
- π CVE-2026-66835 (CVSS 4.0: 8.2)
- π CVE-2026-73270 (CVSS 4.0: 8.2)
π [HIGH] arubanetworks/fabric_composer
1 CVE | CVSS 3.1: 10.0 | AAS 10.2
cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*(<= 7.3.3)
HPE Networking Fabric Composer (formerly Aruba Fabric Composer) is affected by one critical vulnerability (CVE-2026-76658, CVSS 10.0) in its SSH daemon that allows an unauthenticated remote attacker to gain full administrative access without any credentials. Successful exploitation enables arbitrary command execution as a privileged user on the underlying operating system, resulting in complete system compromise. Any organization running AFC should apply the vendor-provided patch immediately, restrict network access to AFC management interfaces, and review the HPE security bulletin for affected versions and detailed remediation steps.
- π CVE-2026-76658 (CVSS 3.1: 10.0)
π [HIGH] wplegalpages/wplp_cookie_consent_βcookie_banner&_consent_management_for_gdpr,ccpa&_google_consent_mode
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:wplegalpages:wplp_cookie_consent_cookie_banner_consent_management_for_gdpr_ccpa_google_consent_mode:*:*:*:*:*:*:*:*
The WPLP Cookie Consent plugin for WordPress, used for GDPR and CCPA cookie banner management, is affected by one critical vulnerability (CVE-2026-75865, CVSS 9.8) in all versions up to and including 4.4.1. The flaw combines an authorization bypass on the WPLP connector REST endpoints with missing file type validation in the saas_upload_logo function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution. WordPress administrators using this plugin should update immediately beyond version 4.4.1, and any site running an affected version should be inspected for signs of compromise, including unexpected files in upload directories.
- π CVE-2026-75865 (CVSS 3.1: 9.8)
π [HIGH] elastic/elasticsearch
1 CVE | CVSS 3.1: 8.8 | AAS 9.6
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Elasticsearch is affected by one high-severity vulnerability (CVE-2026-72649, CVSS 8.8) in its machine learning component, where a specially crafted trained model artifact can trigger deserialization of untrusted data, leading to remote code execution with a broader system-call surface than intended. Exploitation requires an authenticated user with privileges to create and deploy trained models, making this a significant risk in multi-tenant or shared-cluster environments where model deployment permissions are not tightly controlled. Organizations running Elasticsearch with ML features enabled should upgrade to version 8.19.20, 9.4.5, or 9.5.1 immediately and audit which users hold model deployment privileges.
- π CVE-2026-72649 (CVSS 3.1: 8.8)
π [HIGH] elastic/kibana
1 CVE | CVSS 3.1: 8.3 | AAS 9.5
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*(>= 9.3.0, < 9.4.3)
Kibana is affected by one high-severity vulnerability (CVE-2026-63137, CVSS 8.3) involving incorrect authorization in its workflow scheduling functionality. A user with workflow edit permissions can manipulate scheduled workflow executions to run under the privileges of a different, higher-privileged user, enabling unauthorized access to and modification of data beyond their intended authorization scope. Organizations running Kibana should upgrade to version 9.4.3 or later immediately and review workflow configurations and edit permissions to limit exposure until patching is complete.
- π CVE-2026-63137 (CVSS 3.1: 8.3)
π [HIGH] tmt_machine_industry_and_trade_ltd._co./talassoft_industrial_management_software
1 CVE | CVSS 3.1: 9.1 | AAS 9.4
cpe:2.3:a:tmt_machine_industry_and_trade_ltd._co.:talassoft_industrial_management_software:*:*:*:*:*:*:*:*
Talassoft Industrial Management Software by TMT Machine Industry and Trade Ltd. Co. is affected by one critical vulnerability (CVE-2026-18931, CVSS 9.1) involving hard-coded credentials embedded in the application, allowing attackers to retrieve sensitive data. All versions from V.4 through V.15 are affected, and the flaw is considered exploitable, posing a serious risk to any industrial environment relying on this software for operational management. Organizations using Talassoft should upgrade to V.16 or later immediately and review systems for any signs of unauthorized access using the embedded credentials.
- π CVE-2026-18931 (CVSS 3.1: 9.1)
π [HIGH] github/enterprise_server
1 CVE | CVSS 4.0: 8.2 | AAS 9.4
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
GitHub Enterprise Server is affected by one high-severity vulnerability (CVE-2026-18730, CVSS 8.2) involving a server-side request forgery flaw in the Manage API. An unauthenticated attacker can supply a crafted cluster configuration to an exposed endpoint, causing the server to issue outbound requests to an attacker-controlled host, where the weak HMAC authentication on those requests could allow token capture and replay for further unauthorized access. Organizations running GitHub Enterprise Server should upgrade to version 3.17.19 or later immediately and restrict network-level access to the Manage API to trusted hosts only.
- π CVE-2026-18730 (CVSS 4.0: 8.2)
π [HIGH] librenms/librenms
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
LibreNMS, a widely used open-source network monitoring platform, is affected by one high-severity vulnerability (CVE-2026-84190, CVSS 8.7) that enables remote code execution through the AboutController. An authenticated administrator can modify the snmpget configuration parameter to point to a malicious executable, which is then passed to shell_exec without proper validation when the /about endpoint is accessed. Organizations running LibreNMS prior to version 26.5.0 should upgrade immediately, and environments with multiple admin accounts should audit configuration change logs for any unauthorized modifications to SNMP tool paths.
- π CVE-2026-84190 (CVSS 4.0: 8.7)
π [HIGH] modelscope/modelscope
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:modelscope:modelscope:*:*:*:*:*:*:*:*
ModelScope, an open-source machine learning model management framework, is affected by one high-severity vulnerability (CVE-2026-84202, CVSS 8.7) stemming from its use of PyYAML’s unsafe yaml.Loader to parse model configuration files. Attackers can craft malicious model repositories containing poisoned YAML configuration files that execute arbitrary Python code when loaded by unsuspecting users, making this a significant supply-chain risk for any team pulling models from untrusted sources. Organizations using ModelScope should monitor the vendor repository for a patched release, avoid loading models from unverified repositories, and audit any recently downloaded model configurations for suspicious Python object construction tags.
- π CVE-2026-84202 (CVSS 4.0: 8.7)