29 vulnerabilities across 5 products scored HIGH or above on September 17, 2026.
- π΄ CRITICAL: 2
- π HIGH: 27
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_β_dynamic_blocks_form_builder) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-16 bulletin.
π΄ [CRITICAL] patriksimek/vm2
23 CVEs | CVSS 4.0: 10.0 | AAS 12.7
cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*(>= 3.11.4, < 3.11.7)cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*(>= 3.10.1)cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*(>= 3.11.3, < 3.11.7)cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*(>= 3.11.3)cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:*(>= 3.11.0, < 3.11.8)
vm2, a popular JavaScript sandboxing library by patriksimek, is affected by 23 vulnerabilities, including multiple critical remote code execution flaws carrying a maximum CVSS score of 10.0. The most severe issues allow sandboxed code to escape the VM sandbox entirely and execute arbitrary operating system commands on the host, effectively defeating the library’s core security purpose. Exploits are available for these vulnerabilities.
Any application or platform relying on vm2 to safely execute untrusted JavaScript code should treat this as an urgent priority. Teams should upgrade to patched versions as identified in the vendor advisory at the link above, or migrate to a maintained alternative such as isolated-vm, as vm2 has been deprecated by its maintainer. Review the full set of advisories to confirm no additional exposure exists in your environment.
- π΄ CVE-2026-92946 (CVSS 4.0: 10.0)
- π΄ CVE-2026-92937 (CVSS 4.0: 10.0)
- π CVE-2026-92934 (CVSS 4.0: 9.5)
- π CVE-2026-92935 (CVSS 4.0: 9.5)
- π CVE-2026-92960 (CVSS 4.0: 10.0)
- π CVE-2026-92956 (CVSS 4.0: 10.0)
- π CVE-2026-92947 (CVSS 4.0: 10.0)
- π CVE-2026-92941 (CVSS 4.0: 10.0)
- π CVE-2026-92940 (CVSS 4.0: 10.0)
- π CVE-2026-92955 (CVSS 4.0: 10.0)
- π CVE-2026-92938 (CVSS 4.0: 9.4)
- π CVE-2026-92957 (CVSS 4.0: 9.4)
- π CVE-2026-92950 (CVSS 4.0: 9.3)
- π CVE-2026-92942 (CVSS 4.0: 8.7)
- π CVE-2026-92953 (CVSS 4.0: 9.3)
- π CVE-2026-92944 (CVSS 4.0: 9.3)
- π CVE-2026-92954 (CVSS 4.0: 9.2)
- π CVE-2026-92948 (CVSS 4.0: 9.4)
- π CVE-2026-92939 (CVSS 4.0: 9.4)
- π CVE-2026-92951 (CVSS 4.0: 9.4)
- π CVE-2026-92952 (CVSS 4.0: 8.9)
- π CVE-2026-92958 (CVSS 4.0: 8.4)
- π CVE-2026-92961 (CVSS 4.0: 8.7)
π [HIGH] vendurehq/vendure
2 CVEs | CVSS 3.1: 9.1 | AAS 9.9
cpe:2.3:a:vendurehq:vendure:*:*:*:*:*:*:*:*(< 3.7.0)
Vendure, an open-source headless commerce platform by vendurehq, is affected by 2 vulnerabilities with a maximum CVSS score of 9.1. Including at least one high-severity flaw, the most critical issue allows an attacker to hijack existing customer accounts by exploiting the external authentication flow, which attaches new authentication methods to accounts without verifying email ownership.
Organizations running Vendure with custom external authentication strategies should upgrade to version 3.7.0 or later immediately. Review the vendor advisory linked above for full details and confirm that no unauthorized account linkages have occurred in your environment.
- π CVE-2026-63472 (CVSS 3.1: 9.1)
- π CVE-2026-63459 (CVSS 3.1: 8.7)
π [HIGH] sgl-project/sglang
1 CVE | CVSS 4.0: 8.8 | AAS 9.7
cpe:2.3:a:sgl-project:sglang:*:*:*:*:*:*:*:*
SGLang, an open-source LLM serving framework by sgl-project, is affected by a high-severity vulnerability with a CVSS score of 8.8. When running in prefill/decode disaggregation mode, an unauthenticated PUT endpoint on the prefill bootstrap service allows attackers to poison the KV transfer routing table with arbitrary addresses, enabling denial of service or disclosure of internal metadata including session identifiers and tensor-parallel topology.
Teams deploying SGLang through version 0.5.19 in disaggregated inference configurations should restrict network access to the bootstrap service immediately and monitor for unexpected routing table modifications. Check the vendor repository for patches and apply updates as soon as they become available.
- π CVE-2026-92972 (CVSS 4.0: 8.8)
π [HIGH] xagio_seo/xagio_seo
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:xagio_seo:xagio_seo:*:*:*:*:*:*:*:*
Xagio SEO, a WordPress SEO plugin, is affected by a high-severity cross-site request forgery vulnerability with a CVSS score of 8.8. The flaw in versions 7.1.0.43 and earlier allows unauthenticated attackers to trick authenticated administrators into performing unintended actions by visiting a malicious page, potentially leading to unauthorized changes to site configuration.
WordPress site administrators using the Xagio SEO plugin should update to a patched version immediately. Review the Patchstack advisory linked above for remediation details and audit recent administrative activity for any unauthorized modifications.
- π CVE-2026-78295 (CVSS 3.1: 8.8)
π [HIGH] wwbn/avideo
2 CVEs | CVSS 4.0: 9.1 | AAS 9.1
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
AVideo, an open-source video platform by WWBN, is affected by 2 vulnerabilities with a maximum CVSS score of 9.1. Including at least one high-severity flaw, the most critical issue allows attackers who possess a victim’s password to completely bypass PGP second-factor authentication by exploiting a loose equality comparison against an uninitialized session variable, effectively nullifying multi-factor protection.
Organizations running AVideo instances with PGP-based two-factor authentication should treat this as urgent, as it reduces account security to single-factor. Apply patches from the vendor advisory immediately and audit authentication logs for any signs of second-factor bypass exploitation.
- π CVE-2026-92914 (CVSS 4.0: 8.6)
- π CVE-2026-92913 (CVSS 4.0: 9.1)