40 vulnerabilities across 15 products scored HIGH or above on August 10, 2026.
🔴 CRITICAL: 9 🟠 HIGH: 31 Exploit Status Upgrades The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
[UPGRADED] CVE-2026-71558 (apache/fory) — F1: exploitable → functional, AAS: 10.9 → 12.9 (HIGH → CRITICAL). Originally in 2026-08-07 bulletin. [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) — F1: theoretical → poc, AAS: 9.1 → 11.6 (HIGH → HIGH). Originally in 2026-08-07 bulletin. [UPGRADED] CVE-2026-65507 (sergey/aiwu) — F1: exploitable → functional, AAS: 10.9 → 12.9 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) — F1: theoretical → poc, AAS: 10.7 → 13.2 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-34191 (apache/apr-util) — F1: exploitable → functional, AAS: 10.5 → 13.7 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-28139 (wpdreams/ajax_search_lite) — F1: exploitable → functional, AAS: 10.1 → 12.1 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2025-15039 (wso2/wso2_identity_server) — F1: theoretical → itw, AAS: 9.9 → 13.9 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-65583 (apache/cxf) — F1: exploitable → functional, AAS: 9.9 → 11.9 (HIGH → HIGH). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-68079 (apache/cxf) — F1: theoretical → poc, AAS: 9.6 → 12.1 (HIGH → CRITICAL). Originally in 2026-08-06 bulletin. [UPGRADED] CVE-2026-48168 (mervinpraison/praisonai) — F1: exploitable → functional, AAS: 10.8 → 12.8 (HIGH → CRITICAL). Originally in 2026-08-05 bulletin. [UPGRADED] CVE-2026-70478 (flowiseai/flowise) — F1: theoretical → poc, AAS: 9.9 → 12.4 (HIGH → CRITICAL). Originally in 2026-08-04 bulletin. [UPGRADED] CVE-2026-39931 (openemr/openemr) — F1: exploitable → functional, AAS: 9.1 → 11.1 (HIGH → HIGH). Originally in 2026-08-03 bulletin. [UPGRADED] CVE-2026-38447 (osticket/osticket) — F1: theoretical → poc, AAS: 9.6 → 12.1 (HIGH → CRITICAL). Originally in 2026-08-03 bulletin. [UPGRADED] CVE-2026-46713 (misskey-dev/misskey) — F1: theoretical → poc, AAS: 9.1 → 11.6 (HIGH → HIGH). Originally in 2026-08-03 bulletin. 🔴 [CRITICAL] metabase/metabase 2 CVEs | CVSS 4.0: 10.0 | AAS 12.9
...