1 vulnerability across 1 product scored HIGH or above on September 30, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-82901 (themefic/ultra_addons_for_contact_form_7) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-26 bulletin.
- [UPGRADED] CVE-2026-93577 (gitlab/gitlab) โ F1: exploitable โ functional, AAS: 11.9 โ 13.9 (HIGH โ CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) โ F1: exploitable โ functional, AAS: 10.1 โ 12.1 (HIGH โ CRITICAL). Originally in 2026-09-24 bulletin.
๐ [HIGH] pexip/infinity
1 CVE | CVSS 3.1: 9.8 | AAS 9.8
cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Pexip Infinity conferencing platform versions before 38.2, as well as versions 39.0, 39.1, and 40.0, are affected by one critical vulnerability (CVE-2026-103110, CVSS 9.8) involving improper input validation that enables a remote unauthenticated attacker to achieve code execution on Conferencing Nodes. Organizations running Pexip Infinity for video conferencing and collaboration should treat this as a high-priority patch cycle. Administrators should consult the vendor security bulletin at docs.pexip.com and upgrade to a patched release immediately, as no exploit is publicly available yet but the attack requires no authentication or user interaction.
- ๐ CVE-2026-103110 (CVSS 3.1: 9.8)