{
  "day": "2026-08-09",
  "boundary": "UTC calendar day",
  "published_count": 78,
  "by_severity": {
    "CRITICAL": 3,
    "HIGH": 11,
    "MEDIUM": 28,
    "LOW": 36
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19348",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02465,
      "epss_percentile": 0.83184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Aitemi",
      "product": "M300 Wi-Fi Repeater",
      "cwe": "CWE-74",
      "title": "Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19348"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19346",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.02216,
      "epss_percentile": 0.81229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH22",
      "cwe": "CWE-74",
      "title": "Tenda CH22 CertListInfo formCertListInfo command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19346"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-71993",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0135,
      "epss_percentile": 0.69266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "Radix AXE6600",
      "cwe": "CWE-78",
      "title": "MSI Radix AXE6600 v781521 Command Injection via openvpn function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71993"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-19329",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andreahaku",
      "product": "codex_mcp",
      "cwe": "CWE-74",
      "title": "andreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19329"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-19332",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NellyW8",
      "product": "MCP4EDA",
      "cwe": "CWE-74",
      "title": "NellyW8 MCP4EDA run_openlane/view_waveform command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19332"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-19333",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NightTrek",
      "product": "Supabase-MCP",
      "cwe": "CWE-74",
      "title": "NightTrek Supabase-MCP generate_types command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19333"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-19334",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NightTrek",
      "product": "Ollama-mcp",
      "cwe": "CWE-74",
      "title": "NightTrek Ollama-mcp index.ts command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19334"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-19345",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00524,
      "epss_percentile": 0.4224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-862",
      "title": "code-projects Task Management System UpdateTaskStatus.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19345"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-19351",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.40997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dresende",
      "product": "node-sql-query",
      "cwe": "CWE-74",
      "title": "dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19351"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-10595",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00491,
      "epss_percentile": 0.40221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parisneo",
      "product": "parisneo/lollms",
      "cwe": "CWE-23",
      "title": "Path Traversal Vulnerability in parisneo/lollms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10595"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-17510",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JONASBN",
      "product": "Crypt::OpenSSL::PKCS12",
      "cwe": "CWE-476",
      "title": "Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17510"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-19341",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 1200GW",
      "cwe": "CWE-119",
      "title": "UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19341"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-15038",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "InfiniteWP Client",
      "cwe": "CWE-287",
      "title": "InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15038"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-19344",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-74",
      "title": "code-projects Task Management System comment_count_user.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19344"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-19342",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-287",
      "title": "code-projects Task Management System Login index.php improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19342"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-19363",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lmammino",
      "product": "oidc-authorizer",
      "cwe": "CWE-200",
      "title": "lmammino oidc-authorizer Lambda Authorizer handler.rs log file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19363"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-19362",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lmammino",
      "product": "oidc-authorizer",
      "cwe": "CWE-404",
      "title": "lmammino oidc-authorizer Authorization Header Parsing parse_token_from_header.rs parse_token_from_header denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19362"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-19374",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adafap",
      "product": "api-mcp",
      "cwe": "CWE-918",
      "title": "adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19374"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-19375",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dmitriiweb",
      "product": "article-scraper-mcp",
      "cwe": "CWE-918",
      "title": "dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19375"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-19359",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nxp-auto-goldvip",
      "product": "gvip",
      "cwe": "CWE-266",
      "title": "nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19359"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-19376",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uasoft",
      "product": "Badaso",
      "cwe": "CWE-266",
      "title": "Uasoft Badaso File API api.php class permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19376"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-19350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.2821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "ERP",
      "cwe": "CWE-862",
      "title": "Dolibarr ERP TakePOS invoice.php fail authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19350"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-19378",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-79",
      "title": "code-projects Task Management System CommentSave.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19378"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-19356",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MingSoft",
      "product": "MCMS",
      "cwe": "CWE-200",
      "title": "MingSoft MCMS ms-mdiy list information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19356"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-19357",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MingSoft",
      "product": "MCMS",
      "cwe": "CWE-200",
      "title": "MingSoft MCMS ms-mdiy get information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19357"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-19340",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anubissbe",
      "product": "ProjectHub-Mcp",
      "cwe": "CWE-918",
      "title": "anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19340"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-19361",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.2016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macrozheng",
      "product": "mall",
      "cwe": "CWE-640",
      "title": "macrozheng mall mall-portal getAuthCode password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19361"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-18464",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP MAPS PRO",
      "cwe": "CWE-400",
      "title": "WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18464"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-19343",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Task Management System",
      "cwe": "CWE-74",
      "title": "code-projects Task Management System AdminLogin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19343"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-18473",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18473"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-17044",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Iptanus File Upload",
      "cwe": "CWE-89",
      "title": "WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17044"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-12372",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00259,
      "epss_percentile": 0.17841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk/nltk",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in nltk/nltk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12372"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-16988",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GeoDirectory",
      "cwe": "CWE-200",
      "title": "GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16988"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-18032",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.1742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Data Access",
      "cwe": "CWE-200",
      "title": "WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18032"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-18357",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPC Order Tip for WooCommerce",
      "cwe": "CWE-200",
      "title": "WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18357"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-19355",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MingSoft",
      "product": "MCMS",
      "cwe": "CWE-74",
      "title": "MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19355"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-19353",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00241,
      "epss_percentile": 0.15487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-73",
      "title": "DedeCMS Installation Wizard index.php _4_Setup file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19353"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-18465",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP MAPS PRO",
      "cwe": "CWE-22",
      "title": "WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18465"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-18603",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PiWeb Cancel order / Refund request for WooCommerce",
      "cwe": "CWE-862",
      "title": "Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18603"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-17017",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CubeWP Framework",
      "cwe": "CWE-89",
      "title": "CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17017"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-19360",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wongcyrus",
      "product": "ExcelLexBot",
      "cwe": "CWE-266",
      "title": "wongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19360"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-19339",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aliyun",
      "product": "alibabacloud-dataworks-mcp-server",
      "cwe": "CWE-918",
      "title": "aliyun alibabacloud-dataworks-mcp-server initResources.ts ReadResourceRequestSchema server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19339"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-19367",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NocteDefensor",
      "product": "LudusMCP",
      "cwe": "CWE-918",
      "title": "NocteDefensor LudusMCP read_range_config rangeConfig.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19367"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-19352",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mifi",
      "product": "lossless-cut",
      "cwe": "CWE-918",
      "title": "mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19352"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-19358",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "3CORESec",
      "product": "Trapdoor",
      "cwe": "CWE-266",
      "title": "3CORESec Trapdoor DefaultFunction access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19358"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-19347",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewdoctor.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19347"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-19364",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19364"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-17014",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-73",
      "title": "WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17014"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-19354",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lock-upme",
      "product": "OPMS",
      "cwe": "CWE-74",
      "title": "lock-upme OPMS IN Clause message.go sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19354"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-16957",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Slim SEO",
      "cwe": "CWE-639",
      "title": "Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16957"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-19335",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jane-xiaoer",
      "product": "skill-vision-control",
      "cwe": "CWE-22",
      "title": "Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19335"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-16992",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.0615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Create",
      "cwe": "CWE-862",
      "title": "Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16992"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-18037",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Create",
      "cwe": "CWE-862",
      "title": "Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18037"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-16032",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LWS Optimize",
      "cwe": "CWE-79",
      "title": "LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16032"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15534",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LEONT",
      "product": "perl",
      "cwe": "CWE-125",
      "title": "Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15534"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-19366",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00141,
      "epss_percentile": 0.03952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NocteDefensor",
      "product": "LudusMCP",
      "cwe": "CWE-22",
      "title": "NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19366"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-19372",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Handwriting-OCR",
      "product": "handwriting-ocr-mcp-server",
      "cwe": "CWE-22",
      "title": "Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19372"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-19368",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PV-Bhat",
      "product": "gemsuite-mcp",
      "cwe": "CWE-22",
      "title": "PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19368"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-70395",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-943",
      "title": "Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-70395"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-19324",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HelloGGX",
      "product": "shadcn-vue-mcp",
      "cwe": "CWE-22",
      "title": "HelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19324"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-19328",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.0362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aktsmm",
      "product": "skill-ninja-mcp-server",
      "cwe": "CWE-22",
      "title": "aktsmm skill-ninja-mcp-server installer.ts uninstallSkill path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19328"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-19331",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.0362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bazylhorsey",
      "product": "obsidian-mcp-server",
      "cwe": "CWE-22",
      "title": "bazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19331"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-19338",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "automateyournetwork",
      "product": "MCPyATS",
      "cwe": "CWE-22",
      "title": "automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19338"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-19370",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bartekke8it56w2",
      "product": "new-mcp",
      "cwe": "CWE-22",
      "title": "bartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19370"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-19371",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nikolaibibo",
      "product": "claude-comfyui-mcp",
      "cwe": "CWE-22",
      "title": "Nikolaibibo claude-comfyui-mcp comfy_upload_image utils.ts copyFileSync path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19371"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-19336",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pimzino",
      "product": "spec-workflow-mcp",
      "cwe": "CWE-22",
      "title": "Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19336"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-19323",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "azer",
      "product": "react-analyzer-mcp",
      "cwe": "CWE-22",
      "title": "azer react-analyzer-mcp analyze-projec index.ts generateProjectDocs path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19323"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-19325",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IncomeStreamSurfer",
      "product": "roo-code-memory-bank-mcp-server",
      "cwe": "CWE-22",
      "title": "IncomeStreamSurfer roo-code-memory-bank-mcp-server read_memory_bank_file/append_memory_bank_entry index.ts appendMemoryBankEntry path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19325"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-19326",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jevon-Zhong",
      "product": "Ai-doctor",
      "cwe": "CWE-22",
      "title": "Jevon-Zhong Ai-doctor filemanagement.service.ts deleteImage path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19326"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-19327",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "abracadabra50",
      "product": "claude-sesh",
      "cwe": "CWE-22",
      "title": "abracadabra50 claude-sesh enricher.ts enrichSession path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19327"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-19330",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angrysky56",
      "product": "advanced-reasoning-mcp",
      "cwe": "CWE-22",
      "title": "angrysky56 advanced-reasoning-mcp index.ts switch_memory_library path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19330"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-19365",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ichigo3766",
      "product": "image-gen-mcp",
      "cwe": "CWE-22",
      "title": "Ichigo3766 image-gen-mcp upscale_images index.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19365"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-69659",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-502",
      "title": "Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69659"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-17011",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nexter Blocks",
      "cwe": "CWE-345",
      "title": "Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17011"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-19337",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adenot",
      "product": "mcp-google-search",
      "cwe": "CWE-918",
      "title": "adenot mcp-google-search read_webpage index.ts server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19337"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-19373",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00111,
      "epss_percentile": 0.01493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PhialsBasement",
      "product": "KoboldCPP-MCP-Server",
      "cwe": "CWE-918",
      "title": "PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19373"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-19369",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KS-GEN-AI",
      "product": "jira-mcp-server",
      "cwe": "CWE-918",
      "title": "KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19369"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-16965",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Solace Extra",
      "cwe": "CWE-352",
      "title": "Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16965"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-9242",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-9242 (WatchGuard Fireware OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10849 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11974",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11974 (Unknown wp-media-folder-addon). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13692",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13692 (Unknown PayU CommercePro Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14188",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14188 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14221 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14222",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14222 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14223",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14223 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14224",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14224 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14226",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14226 (Unknown Easy Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16535",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16535 (Unknown Link Library). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16558 (Unknown YMC Filter). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16562",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16562 (Unknown WP Statistics). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16578",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16578 (Unknown Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16590",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16590 (Unknown WP Directory Kit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16594",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16594 (Unknown WP Directory Kit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16595",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16595 (Unknown WP Directory Kit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19211 (SourceCodester Photo Share Website). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19231",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19231 (SourceCodester Simple Doctors Appointment System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19245",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19245 (HKUDS nanobot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19259",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19259 (MZ Automation libiec61850). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19268",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19268 (abdullah1854 MCPGateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67620 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71959 (bitwarden server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72743",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72743 (dataease SQLBot). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-63077",
      "detail": "DUE DATE PASSED — CVE-2026-63077 (JetBrains TeamCity). CISA remediation deadline was August 8, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16089",
      "detail": "RESCORED — CVE-2026-16089 (Red Hat Build of Keycloak). CVSS 5.4 → 5.9 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-72898",
      "detail": "PATCH SHIPPED — CVE-2026-72898 (Metabase). Fixed in Metabase x.58.24."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-23385",
      "detail": "ENRICHED — CVE-2026-23385 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
