3 vulnerabilities across 3 products scored HIGH or above on September 18, 2026.
- ๐ HIGH: 3
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_โ_dynamic_blocks_form_builder) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-16 bulletin.
๐ [HIGH] microsoft/azure_horizondb
1 CVE | CVSS 3.1: 9.9 | AAS 9.2
cpe:2.3:a:microsoft:azure_horizondb:*:*:*:*:*:*:*:*
Microsoft Azure HorizonDB โ 1 Critical Vulnerability
A critical privilege escalation vulnerability (CVE-2026-85878, CVSS 9.9) affects Microsoft Azure Database for PostgreSQL. The flaw stems from improper authorization controls, allowing an authenticated attacker to elevate privileges over the network. This vulnerability is considered exploitable. Teams running Azure Database for PostgreSQL workloads should review the vendor advisory immediately and apply any available mitigations or patches. Refer to the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85878 for detailed guidance and affected version information.
- ๐ CVE-2026-85878 (CVSS 3.1: 9.9)
๐ [HIGH] xerial/snappy-java
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*
Xerial snappy-java โ 1 High-Severity Vulnerability
A high-severity buffer overflow vulnerability (CVE-2026-93452, CVSS 8.7) affects snappy-java through version 1.1.10.8. The flaw resides in the Snappy.compress(ByteBuffer, ByteBuffer) method, where specially crafted incompressible input data can cause writes past the end of the destination buffer, corrupting off-heap memory and crashing the JVM. This vulnerability is considered exploitable. Any Java application using snappy-java for compression should be reviewed, particularly services that accept untrusted input for compression. Teams should upgrade to a patched version of snappy-java as soon as one is available and monitor the project repository at https://github.com/xerial/snappy-java for release updates.
- ๐ CVE-2026-93452 (CVSS 4.0: 8.7)
๐ [HIGH] shortpixel/shortpixel_image_optimizer_โ_optimize_images,convert_webp&_avif
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:shortpixel:shortpixel_image_optimizer_optimize_images_convert_webp_avif:*:*:*:*:*:*:*:*(< 6.5.6)
ShortPixel Image Optimizer โ 1 High-Severity Vulnerability
A high-severity PHP Object Injection vulnerability (CVE-2026-17086, CVSS 8.8) affects the ShortPixel Image Optimizer plugin for WordPress in all versions through 6.5.5. Authenticated attackers with author-level privileges or higher can exploit insecure deserialization to inject arbitrary PHP objects, which becomes especially dangerous when another plugin or theme on the site provides a usable POP chain. WordPress administrators running this plugin should update to a patched version immediately and audit their sites for additional plugins that could extend the exploitability of this flaw.
- ๐ CVE-2026-17086 (CVSS 3.1: 8.8)