1 vulnerability across 1 product scored HIGH or above on October 11, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-104334 (langflow/langflow) โ€” F1: exploitable โ†’ functional, AAS: 13.4 โ†’ 15.4 (CRITICAL โ†’ CRITICAL). Originally in 2026-10-07 bulletin.
  • [UPGRADED] CVE-2026-106382 (google/chrome) โ€” F1: exploitable โ†’ functional, AAS: 11.4 โ†’ 13.4 (HIGH โ†’ CRITICAL). Originally in 2026-10-06 bulletin.
  • [UPGRADED] CVE-2026-105697 (langflow-ai/langflow) โ€” F1: exploitable โ†’ functional, AAS: 10.2 โ†’ 12.7 (HIGH โ†’ CRITICAL). Originally in 2026-10-05 bulletin.

๐ŸŸ  [HIGH] scisharp/botsharp

1 CVE | CVSS 4.0: 9.3 | AAS 9.6

  • cpe:2.3:a:scisharp:botsharp:*:*:*:*:*:*:*:*

BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json.

Vendor Advisory