8 vulnerabilities across 6 products scored HIGH or above on September 13, 2026.
- π HIGH: 8
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) β F1: exploitable β functional, AAS: 12.1 β 15.1 (CRITICAL β CRITICAL). Originally in 2026-09-08 bulletin.
- [UPGRADED] CVE-2026-75650 (adobe/commerce) β F1: exploitable β itw, AAS: 14.1 β 17.1 (CRITICAL β EMERGENCY). Originally in 2026-09-07 bulletin.
π [HIGH] lfnovo/open-notebook
1 CVE | CVSS 4.0: 8.3 | AAS 9.2
cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*(< 1.11.0)
Open Notebook by lfnovo versions prior to 1.11.0 are affected by one HIGH-severity vulnerability (CVE-2026-90769, CVSS 8.3) involving a server-side request forgery (SSRF) flaw in the /api/sources endpoint. An authenticated attacker can supply arbitrary URLs to force the server into making requests to internal services, cloud metadata endpoints, and localhost-bound resources, potentially exposing sensitive infrastructure data. Teams running Open Notebook should upgrade to version 1.11.0 or later immediately and review the vendor advisory on GitHub for additional details.
- π CVE-2026-90769 (CVSS 4.0: 8.3)
π [HIGH] openspug/spug
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:openspug:spug:*:*:*:*:*:*:*:*
Spug by openspug through version 3.4.0 is affected by one HIGH-severity remote code execution vulnerability (CVE-2026-90770, CVSS 8.7) stemming from unsanitized user input in the ping_check function. Authenticated users with monitor permissions can inject shell metacharacters through the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user. Organizations running Spug should check the vendor advisory on GitHub for patches or mitigations, restrict monitor permissions to trusted accounts, and consider network-level controls to limit access to the affected endpoint.
- π CVE-2026-90770 (CVSS 4.0: 8.7)
π [HIGH] espnet/espnet
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:espnet:espnet:*:*:*:*:*:*:*:*(< 202609)
ESPnet versions prior to 202609 are affected by one HIGH-severity vulnerability (CVE-2026-90777, CVSS 8.7) involving unsafe deserialization of model checkpoints via torch.load with weights_only=False. An attacker who can supply a crafted checkpoint file can achieve arbitrary code execution when the model is loaded during initialization or fine-tuning workflows. Teams using ESPnet for speech processing should upgrade to version 202609 or later, only load checkpoints from trusted sources, and review the vendor advisory on GitHub for further guidance.
- π CVE-2026-90777 (CVSS 4.0: 8.7)
π [HIGH] orhun/rustypaste
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:orhun:rustypaste:*:*:*:*:*:*:*:*(< 0.18.1)
rustypaste by orhun versions prior to 0.18.1 are affected by one HIGH-severity path traversal vulnerability (CVE-2026-90774, CVSS 8.7) where directory-escape validation is applied before the custom filename header is processed, allowing attackers to bypass protections and write files to arbitrary locations on the server. This can lead to remote code execution or system compromise depending on the deployment environment and file permissions. Administrators running rustypaste should upgrade to version 0.18.1 or later immediately and review the vendor advisory on GitHub for details.
- π CVE-2026-90774 (CVSS 4.0: 8.7)
π [HIGH] sipp/sipp
3 CVEs | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:sipp:sipp:*:*:*:*:*:*:*:*
SIPp through version 3.7.7 is affected by three HIGH-severity vulnerabilities (CVE-2026-90780, CVE-2026-90779, CVE-2026-90778, max CVSS 8.7) including multiple buffer overflow and parsing flaws in SIP message handling. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to crash the process or potentially achieve code execution, posing a significant risk to VoIP testing and telecommunications environments. Teams using SIPp should monitor the vendor advisory on GitHub for patches, restrict network exposure of SIPp instances, and consider upgrading as soon as a fix is available.
- π CVE-2026-90780 (CVSS 4.0: 8.7)
- π CVE-2026-90779 (CVSS 4.0: 8.7)
- π CVE-2026-90778 (CVSS 4.0: 8.7)
π [HIGH] langbot-app/langbot
1 CVE | CVSS 4.0: 9.2 | AAS 9.0
cpe:2.3:a:langbot-app:langbot:*:*:*:*:*:*:*:*(< 4.10.11)
LangBot by langbot-app versions prior to 4.10.11 are affected by one HIGH-severity vulnerability (CVE-2026-90562, CVSS 9.2) where password recovery keys are generated with only 24 bits of entropy and the reset-password endpoint lacks rate limiting. A remote unauthenticated attacker who knows an administrator’s email address can brute-force the recovery key space to reset the admin password and take over the account. Organizations running LangBot should upgrade to version 4.10.11 or later immediately and review the vendor advisory on GitHub for additional mitigations.
- π CVE-2026-90562 (CVSS 4.0: 9.2)