2 vulnerabilities across 1 product scored HIGH or above on September 12, 2026.

  • ๐Ÿ”ด CRITICAL: 1
  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) โ€” F1: exploitable โ†’ functional, AAS: 12.1 โ†’ 15.1 (CRITICAL โ†’ CRITICAL). Originally in 2026-09-08 bulletin.
  • [UPGRADED] CVE-2026-75650 (adobe/commerce) โ€” F1: exploitable โ†’ itw, AAS: 14.1 โ†’ 17.1 (CRITICAL โ†’ EMERGENCY). Originally in 2026-09-07 bulletin.

๐Ÿ”ด [CRITICAL] gitlab/gitlab

2 CVEs | CVSS 3.1: 10.0 | AAS 15.6

  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

GitLab CE/EE contains two critical vulnerabilities, including at least one rated CVSS 10.0, affecting all versions from 18.7 through unpatched releases of 19.1, 19.2, and 19.3. The most severe issue allows unauthenticated attackers to read arbitrary files from the GitLab server by exploiting improper path confinement and missing authentication in the repository commits API, and exploitation has been observed in the wild. Security teams running self-managed GitLab instances should treat this as an emergency and upgrade immediately to 19.1.8, 19.2.6, or 19.3.2, referring to the vendor advisory for full details.

Vendor Advisory