Daily curated vulnerability bulletins from ARETIQ AI. Each bulletin highlights the day’s most critical vulnerabilities, ranked by real-world risk — not just CVSS scores.
Ranked by AAS (ARETIQ Adjusted Score) — a real-world risk score that considers exploit maturity, deployment scale, asset criticality, and remediation status.
Subscribe via JSON feed.
No EMERGENCY vulnerabilities this month.
Daily Bulletins#
33 vulnerabilities across 15 products scored HIGH or above on September 18, 2026.
🔴 CRITICAL: 3 🟠 HIGH: 30 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_—_dynamic_blocks_form_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-16 bulletin. 🔴 [CRITICAL] patriksimek/vm2 3 CVEs | CVSS 4.0: 10.0 | AAS 12.7
cpe:2.3:a:patriksimek:vm2:*:*:*:*:*:*:*:* (< 3.12.1) vm2 by patriksimek — 3 Critical Vulnerabilities Including Sandbox Escape
...
43 vulnerabilities across 15 products scored HIGH or above on September 17, 2026.
🔴 CRITICAL: 4 🟠 HIGH: 39 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-12793 (jetmonsters/jetformbuilder_—_dynamic_blocks_form_builder) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-09-16 bulletin. 🔴 [CRITICAL] chamilo/chamilo-lms 2 CVEs | CVSS 3.1: 9.8 | AAS 13.4
cpe:2.3:a:chamilo:chamilo-lms:*:*:*:*:*:*:*:* (< 2.0.1) cpe:2.3:a:chamilo:chamilo-lms:*:*:*:*:*:*:*:* (>= 2.0.0) Chamilo LMS versions prior to 2.0.1 are affected by 2 critical vulnerabilities, including at least one that allows an unauthenticated remote attacker to execute arbitrary code on the server (CVSS 9.8). Organizations running Chamilo LMS in educational or training environments should treat this as an urgent priority, as the flaw requires no authentication and exploitation is considered feasible. Upgrade to Chamilo LMS 2.0.1 immediately and review the vendor advisory at the Chamilo GitHub security page for additional details.
...
27 vulnerabilities across 15 products scored HIGH or above on September 16, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 26 🔴 [CRITICAL] cisco/cisco_identity_services_engine_software 1 CVE | CVSS 3.1: 10.0 | AAS 13.3
cpe:2.3:a:cisco:cisco_identity_services_engine_software:*:*:*:*:*:*:*:* Cisco Identity Services Engine (ISE) is affected by a critical authentication bypass vulnerability (CVE-2026-76460, CVSS 10.0) in an API endpoint that allows unauthenticated remote attackers to gain unauthorized access to the web-based management interface. This vulnerability is confirmed exploited in the wild, making immediate action essential for any organization running Cisco ISE for network access control and policy enforcement.
...
42 vulnerabilities across 15 products scored HIGH or above on September 15, 2026.
🔴 CRITICAL: 9 🟠 HIGH: 33 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion) — F1: exploitable → functional, AAS: 12.1 → 15.6 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. 🔴 [CRITICAL] oracle_corporation/oracle_weblogic_server 5 CVEs | CVSS 3.1: 10.0 | AAS 13.9
cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:* (>= 12.2.1.4.0) cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:* (>= 14.1.1.0.0) cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:* (>= 14.1.2.0.0) cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:* (>= 15.1.1.0.0) cpe:2.3:a:oracle:oracle_weblogic_server:*:*:*:*:*:*:*:* (>= 12.2.1.4.0, < 12.2.1.4.0) Oracle WebLogic Server is affected by five vulnerabilities, including at least one rated CRITICAL with a CVSS score of 10.0. The most severe issue resides in the Core component and allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full takeover of the server without any user interaction. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
...
22 vulnerabilities across 15 products scored HIGH or above on September 14, 2026.
🔴 CRITICAL: 2 🟠 HIGH: 20 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion) — F1: exploitable → functional, AAS: 12.1 → 15.6 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-75650 (adobe/commerce) — F1: exploitable → itw, AAS: 14.1 → 17.1 (CRITICAL → EMERGENCY). Originally in 2026-09-07 bulletin. 🔴 [CRITICAL] cisco/cisco_secure_email 2 CVEs | CVSS 3.1: 9.8 | AAS 13.4
...
8 vulnerabilities across 6 products scored HIGH or above on September 13, 2026.
🟠 HIGH: 8 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) — F1: exploitable → functional, AAS: 12.1 → 15.1 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-75650 (adobe/commerce) — F1: exploitable → itw, AAS: 14.1 → 17.1 (CRITICAL → EMERGENCY). Originally in 2026-09-07 bulletin. 🟠 [HIGH] lfnovo/open-notebook 1 CVE | CVSS 4.0: 8.3 | AAS 9.2
...
8 vulnerabilities across 6 products scored HIGH or above on September 12, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 7 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) — F1: exploitable → functional, AAS: 12.1 → 15.1 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-75650 (adobe/commerce) — F1: exploitable → itw, AAS: 14.1 → 17.1 (CRITICAL → EMERGENCY). Originally in 2026-09-07 bulletin. 🔴 [CRITICAL] gitlab/gitlab 2 CVEs | CVSS 3.1: 10.0 | AAS 15.6
...
26 vulnerabilities across 12 products scored HIGH or above on September 11, 2026.
🟠 HIGH: 26 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) — F1: exploitable → functional, AAS: 12.1 → 15.1 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-75650 (adobe/commerce) — F1: exploitable → itw, AAS: 14.1 → 17.1 (CRITICAL → EMERGENCY). Originally in 2026-09-07 bulletin. 🟠 [HIGH] designcomputer/mysql-mcp-server 1 CVE | CVSS 3.1: 10.0 | AAS 11.2
...
30 vulnerabilities across 13 products scored HIGH or above on September 10, 2026.
🟠 HIGH: 30 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) — F1: exploitable → functional, AAS: 12.1 → 15.1 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-75650 (adobe/commerce) — F1: exploitable → itw, AAS: 14.1 → 17.1 (CRITICAL → EMERGENCY). Originally in 2026-09-07 bulletin. [UPGRADED] CVE-2026-85046 (google/chrome) — F1: exploitable → functional, AAS: 10.6 → 12.6 (HIGH → CRITICAL). Originally in 2026-09-03 bulletin. 🟠 [HIGH] diegosouzapw/omniroute 1 CVE | CVSS 4.0: 9.5 | AAS 11.3
...
15 vulnerabilities across 11 products scored HIGH or above on September 09, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 14 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-48273 (adobe/coldfusion_2025) — F1: exploitable → functional, AAS: 12.1 → 15.1 (CRITICAL → CRITICAL). Originally in 2026-09-08 bulletin. [UPGRADED] CVE-2026-85046 (google/chrome) — F1: exploitable → functional, AAS: 10.6 → 12.6 (HIGH → CRITICAL). Originally in 2026-09-03 bulletin. [UPGRADED] CVE-2026-20212 (cisco/cisco_nx-os_software) — F1: theoretical → poc, AAS: 10.9 → 13.4 (HIGH → CRITICAL). Originally in 2026-09-02 bulletin. 🔴 [CRITICAL] parse-community/parse-server 1 CVE | CVSS 4.0: 9.1 | AAS 12.0
...