21 vulnerabilities across 13 products scored HIGH or above on September 02, 2026.

  • πŸ”΄ CRITICAL: 1
  • 🟠 HIGH: 20

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-65641 (veeam/one) β€” F1: exploitable β†’ functional, AAS: 10.4 β†’ 12.4 (HIGH β†’ CRITICAL). Originally in 2026-08-26 bulletin.

πŸ”΄ [CRITICAL] craftcms/cms

5 CVEs | CVSS 4.0: 9.2 | AAS 12.2

  • cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*

Craft CMS versions prior to 5.10.11 are affected by five vulnerabilities, including at least one rated CRITICAL with a CVSS 4.0 score of 9.2. The most severe issue allows attackers to gain full administrator privileges by registering with a deactivated admin’s email address, exploiting a flaw where the admin flag is not properly cleared during user registration. This is exploitable in environments where public registration is enabled and email verification is disabled. Security teams running Craft CMS should update to version 5.10.11 or later immediately and review the vendor advisory at the link above for details on all five issues. Organizations should also audit their Craft CMS instances for any unauthorized admin accounts that may have been created through this registration bypass.

Vendor Advisory


🟠 [HIGH] cisco/cisco_ios_xr_software

1 CVE | CVSS 3.1: 9.8 | AAS 11.9

  • cpe:2.3:a:cisco:cisco_ios_xr_software:*:*:*:*:*:*:*:*

Cisco IOS XR Software is affected by a vulnerability rated CRITICAL with a CVSS 3.1 score of 9.8, stemming from improper resource control issues identified during an internal security review. The flaw could allow an attacker to exploit resource handling weaknesses in affected IOS XR deployments, and Cisco considers it exploitable. Network teams running Cisco IOS XR should apply the hardening release immediately and consult the vendor advisory for affected version details and upgrade guidance.

Vendor Advisory


🟠 [HIGH] as203038/looking-glass

1 CVE | CVSS 3.1: 9.8 | AAS 11.9

  • cpe:2.3:a:as203038:looking-glass:*:*:*:*:*:*:*:* (< 1.3.5)

AS203038 Looking Glass, a network diagnostic platform used to expose ping, traceroute, and BGP lookups through routers via SSH, is affected by a critical OS command injection vulnerability with a CVSS 3.1 score of 9.8. An unanchored regular expression in the input validation layer allows attackers to inject arbitrary commands, potentially compromising the underlying system and any routers managed by the platform. Network operations teams running Looking Glass prior to version 1.3.5 should update immediately, as the issue is considered exploitable and the fix is available in the patched release.

Vendor Advisory


🟠 [HIGH] cisco/cisco_nx-os_software

1 CVE | CVSS 3.1: 9.8 | AAS 10.9

  • cpe:2.3:a:cisco:cisco_nx-os_software:*:*:*:*:*:*:*:*

Cisco Nexus 9000 Series Switches using the Silicon One integration are affected by a remote code execution vulnerability with a CVSS 3.1 score of 9.8. The flaw exposes TCP ports 43210 and 43211 in the default Layer 3 VRF, allowing an unauthenticated remote attacker to send crafted input and execute code with root privileges on the device. Organizations running affected Nexus 9000 switches should review the vendor advisory for impacted software versions and apply patches as soon as possible, as no authentication is required to exploit this issue.

Vendor Advisory


🟠 [HIGH] jenkins_project/jenkins

5 CVEs | CVSS 3.1: 8.8 | AAS 10.7

  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* (>= 2.447, < 2.580)
  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* (>= 2.452.1, < 2.568.3)
  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* (>= 2.568.1, < 2.568.3)
  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* (>= 2.568, < 2.568.3)

Jenkins versions 2.579 and earlier and LTS 2.568.2 and earlier are affected by five vulnerabilities, including multiple considered exploitable, with the highest carrying a CVSS 3.1 score of 8.8. The most notable issue is a stored cross-site scripting flaw in the system log viewer where log record metadata is not properly escaped, allowing attackers who control agent processes to execute malicious scripts in the context of Jenkins administrators viewing logs. Teams running Jenkins should update to the latest release immediately and review the September 2nd security advisory for full details on all five issues.

Vendor Advisory


🟠 [HIGH] coollabsio/coolify

1 CVE | CVSS 4.0: 8.7 | AAS 10.3

  • cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*

Coolify, an open-source self-hosting platform, versions prior to 4.2.0 are affected by a command injection vulnerability with a CVSS 4.0 score of 8.7. Authenticated attackers can inject shell metacharacters into environment variable key names, which are passed unescaped into Docker commands executed over SSH, allowing arbitrary command execution on the managed server host outside of containers. Teams using Coolify to manage deployments should update to version 4.2.0 or later immediately, as this flaw enables a full container escape path for any authenticated user.

Vendor Advisory


🟠 [HIGH] totolink/cp450

1 CVE | CVSS 4.0: 9.4 | AAS 10.2

  • cpe:2.3:a:totolink:cp450:*:*:*:*:*:*:*:* (>= 4.1.0)

TOTOLINK CP450 version 4.1.0 is affected by a remotely exploitable buffer overflow vulnerability with a CVSS 4.0 score of 9.4. The flaw exists in the cstecgi.cgi handler, where manipulation of the topicurl argument allows a remote attacker to trigger a buffer overflow, potentially leading to device compromise. Organizations deploying TOTOLINK CP450 access points should check for firmware updates from the vendor immediately and, if no patch is available, restrict network access to the device’s management interface as a mitigation.

Vendor Advisory


🟠 [HIGH] melograno/booking_for_appointments_and_events_calendar_–_amelia

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:melograno:booking_for_appointments_and_events_calendar_amelia:*:*:*:*:*:*:*:*

The Amelia Booking for Appointments and Events Calendar premium plugin for WordPress versions 8.0 through 9.6.2 is affected by a privilege escalation vulnerability with a CVSS 3.1 score of 9.8. Unauthenticated attackers can exploit insufficient validation in the customer update endpoint to elevate their role to manager and create a WordPress user account with administrative plugin privileges, requiring no authentication whatsoever. WordPress site administrators using the Amelia premium plugin should update beyond version 9.6.2 immediately, as this flaw provides a direct path to site compromise for any remote attacker.

Vendor Advisory


🟠 [HIGH] jenkins_project/jenkins_file_parameter_plugin

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:jenkins:jenkins_file_parameter_plugin:*:*:*:*:*:*:*:*

Jenkins File Parameter Plugin version 425.v3fa_801681b_5e and earlier is affected by an arbitrary file write vulnerability with a CVSS 3.1 score of 8.8 that can lead to remote code execution. The flaw allows attackers to write files to arbitrary locations on the Jenkins controller file system through Stapler data binding, enabling full server compromise. Jenkins administrators using the File Parameter Plugin should update to the latest patched version immediately and review the September 2nd security advisory for remediation details.

Vendor Advisory


🟠 [HIGH] wc_lovers/wcfm_marketplace

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:wc_lovers:wcfm_marketplace:*:*:*:*:*:*:*:*

WCFM Marketplace, a popular multi-vendor marketplace plugin for WooCommerce on WordPress, versions 3.8.1 and earlier are affected by an unauthenticated SQL injection vulnerability with a CVSS 3.1 score of 9.3. The flaw requires no authentication to exploit, allowing remote attackers to directly interact with the WordPress database to extract sensitive data, modify content, or potentially escalate to full site compromise. WordPress site administrators running WCFM Marketplace should update beyond version 3.8.1 immediately and review database logs for any signs of exploitation.

Vendor Advisory


🟠 [HIGH] toon-format/toon

1 CVE | CVSS 3.1: 8.3 | AAS 9.6

  • cpe:2.3:a:toon-format:toon:*:*:*:*:*:*:*:* (< 2.3.1)

TOON, a serialization format for JSON data commonly used in LLM prompts, versions prior to 2.3.1 are affected by a prototype pollution vulnerability with a CVSS 3.1 score of 8.3. Decoding attacker-controlled TOON input containing proto, constructor, or prototype keys allows pollution of Object.prototype for the entire JavaScript runtime, which can lead to denial of service, authentication bypass, or remote code execution depending on the application. Development teams using the TOON package should update to version 2.3.1 or later immediately, particularly in any service that processes untrusted serialized input such as LLM pipelines.

Vendor Advisory


🟠 [HIGH] nsquared/simply_schedule_appointments

1 CVE | CVSS 3.1: 8.8 | AAS 9.1

  • cpe:2.3:a:nsquared:simply_schedule_appointments:*:*:*:*:*:*:*:*

Simply Schedule Appointments, a WordPress scheduling plugin, versions 1.6.12.23 and earlier are affected by an unauthenticated cross-site request forgery vulnerability with a CVSS 3.1 score of 8.8. The flaw allows attackers to craft malicious requests that execute privileged actions on behalf of authenticated administrators who visit a compromised or attacker-controlled page, without requiring any prior authentication. WordPress site administrators using Simply Schedule Appointments should update beyond version 1.6.12.23 as soon as a patch is available and review the Patchstack advisory for additional mitigation guidance.

Vendor Advisory


🟠 [HIGH] nuclio/nuclio

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:nuclio:nuclio:*:*:*:*:*:*:*:* (< 1.17.4)

Nuclio, a serverless framework for real-time data processing, versions prior to 1.17.4 are affected by an unauthenticated OS command injection vulnerability in the dashboard with a CVSS 4.0 score of 8.7. A previous fix for command injection was incomplete, leaving the list-all resource path exposed where the resourceNamespace parameter is interpolated unquoted into shell commands, allowing remote attackers to execute arbitrary commands on the host. Teams running Nuclio on the local or Docker platform should update to version 1.17.4 immediately, as this flaw requires no authentication and provides direct command execution on the underlying system.

Vendor Advisory