8 vulnerabilities across 6 products scored HIGH or above on September 25, 2026.
🟠 HIGH: 8 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-24 bulletin. [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) — F1: exploitable → functional, AAS: 9.6 → 11.6 (HIGH → HIGH). Originally in 2026-09-22 bulletin. [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) — F1: exploitable → functional, AAS: 11.2 → 13.2 (HIGH → CRITICAL). Originally in 2026-09-21 bulletin. [UPGRADED] CVE-2026-92229 (wpmudev/forminator) — F1: exploitable → functional, AAS: 9.9 → 11.9 (HIGH → HIGH). Originally in 2026-09-19 bulletin. [UPGRADED] CVE-2026-89274 (bootstrapped_ventures/wp_recipe_maker) — F1: exploitable → functional, AAS: 9.4 → 11.4 (HIGH → HIGH). Originally in 2026-09-19 bulletin. [UPGRADED] CVE-2026-93603 (patriksimek/vm2) — F1: exploitable → functional, AAS: 12.7 → 14.7 (CRITICAL → CRITICAL). Originally in 2026-09-18 bulletin. [UPGRADED] CVE-2026-93605 (patriksimek/vm2) — F1: exploitable → functional, AAS: 12.7 → 14.7 (CRITICAL → CRITICAL). Originally in 2026-09-18 bulletin. [UPGRADED] CVE-2026-93606 (patriksimek/vm2) — F1: theoretical → functional, AAS: 11.7 → 14.7 (HIGH → CRITICAL). Originally in 2026-09-18 bulletin. [UPGRADED] CVE-2026-82340 (ibm/guardium_data_protection) — F1: exploitable → functional, AAS: 10.9 → 12.9 (HIGH → CRITICAL). Originally in 2026-09-18 bulletin. [UPGRADED] CVE-2026-81657 (ibm/guardium_data_protection) — F1: exploitable → functional, AAS: 10.9 → 12.9 (HIGH → CRITICAL). Originally in 2026-09-18 bulletin. [UPGRADED] CVE-2026-84383 (strukturag/libheif) — F1: exploitable → functional, AAS: 10.9 → 12.9 (HIGH → CRITICAL). Originally in 2026-09-18 bulletin. 🟠 [HIGH] gestsup/gestsup 1 CVE | CVSS 4.0: 9.2 | AAS 10.2
...