2 vulnerabilities across 2 products scored HIGH or above on September 02, 2026.
- ๐ HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-65641 (veeam/one) โ F1: exploitable โ functional, AAS: 10.4 โ 12.4 (HIGH โ CRITICAL). Originally in 2026-08-26 bulletin.
๐ [HIGH] melograno/booking_for_appointments_and_events_calendar_โ_amelia
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:melograno:booking_for_appointments_and_events_calendar_amelia:*:*:*:*:*:*:*:*(>= 8.0, < 9.6.3)
Melograno Booking for Appointments and Events Calendar โ Amelia (WordPress Plugin)
One critical vulnerability (CVE-2026-9055, CVSS 9.8) affects the Amelia premium WordPress plugin versions 8.0 through 9.6.2. The flaw allows unauthenticated attackers to escalate privileges by manipulating parameters in the customer update endpoint, enabling them to create WordPress accounts with the wpamelia-manager role and gain unauthorized administrative access to the booking system. Any WordPress site running the Amelia premium plugin in the affected version range is at risk, and exploitation requires no authentication.
Site administrators should update the Amelia plugin beyond version 9.6.2 immediately. Given the unauthenticated nature of this vulnerability, organizations should also audit their WordPress user lists for any unexpected accounts with the wpamelia-manager role, which may indicate prior compromise. Refer to the Wordfence advisory for additional technical details.
- ๐ CVE-2026-9055 (CVSS 3.1: 9.8)
๐ [HIGH] coollabsio/coolify
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*
Coollabs Coolify
One high-severity vulnerability (CVE-2026-84694, CVSS 8.7) affects Coolify versions prior to 4.2.0. Authenticated users can inject shell metacharacters into environment variable key names, which are insufficiently escaped when passed to Docker commands executed over SSH on managed servers, allowing arbitrary command execution on the host system outside of container boundaries. Organizations using Coolify to manage containerized deployments should treat this as a container escape path that could compromise the underlying infrastructure.
Administrators should upgrade Coolify to version 4.2.0 or later immediately and review audit logs for any suspicious environment variable configurations that may indicate prior exploitation. Given that the flaw enables host-level command execution from within the Coolify management interface, any managed server connected to a vulnerable Coolify instance should be considered potentially affected.
- ๐ CVE-2026-84694 (CVSS 4.0: 8.7)