{
  "day": "2026-08-29",
  "boundary": "UTC calendar day",
  "published_count": 67,
  "by_severity": {
    "CRITICAL": 11,
    "HIGH": 18,
    "MEDIUM": 29,
    "LOW": 7
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 2,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-76547",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Profile Builder",
      "cwe": "CWE-502",
      "title": "Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76547"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-80725",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00191,
      "epss_percentile": 0.08826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: gro: properly validate BIG TCP aggregation criteria",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80725"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-16061",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rest Routes",
      "cwe": "CWE-89",
      "title": "Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16061"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-77008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HEL Online Classroom: AI-powered Online Classrooms",
      "cwe": "CWE-284",
      "title": "HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77008"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-80488",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate CSV Importer",
      "cwe": "CWE-89",
      "title": "WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80488"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-76546",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Profile Builder",
      "cwe": "CWE-79",
      "title": "Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76546"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-81026",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-284",
      "title": "MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81026"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-10522",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00147,
      "epss_percentile": 0.04236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MemberHero",
      "cwe": null,
      "title": "Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10522"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-77007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HEL Online Classroom: AI-powered Online Classrooms",
      "cwe": "CWE-200",
      "title": "HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77007"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-16259",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Uix UserCenter",
      "cwe": "CWE-269",
      "title": "Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16259"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-77012",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "爱采集数据采集和发布插件",
      "cwe": "CWE-918",
      "title": "Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77012"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-16947",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.03357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Total processing card payments for WooCommerce",
      "cwe": "CWE-918",
      "title": "Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16947"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-76586",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Booking Calendar Plugin and Scheduling Plugin",
      "cwe": "CWE-284",
      "title": "BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76586"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-77010",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "HEL Online Classroom: AI-powered Online Classrooms",
      "cwe": "CWE-284",
      "title": "HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77010"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-19430",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Catfolders Document Gallery Pro",
      "cwe": "CWE-862",
      "title": "CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19430"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-81342",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-601",
      "title": "MasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81342"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-76548",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Profile Builder",
      "cwe": "CWE-287",
      "title": "Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76548"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-16600",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SmartAIPress",
      "cwe": "CWE-918",
      "title": "SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16600"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-18233",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18233"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-18234",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18234"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-77786",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rank Math SEO",
      "cwe": "CWE-863",
      "title": "Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77786"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-80311",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Stripe Payment Forms by WP Full Pay",
      "cwe": "CWE-639",
      "title": "Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80311"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-81346",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-862",
      "title": "Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81346"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-77704",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Booking for Appointments and Events Calendar",
      "cwe": "CWE-863",
      "title": "Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77704"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-81200",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81200"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-17520",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-326",
      "title": "Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17520"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-17522",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Newsletters",
      "cwe": "CWE-352",
      "title": "Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17522"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-41012",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00095,
      "epss_percentile": 0.0069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry",
      "product": "bosh-vsphere-cpi-release",
      "cwe": "CWE-295",
      "title": "BOSH vSphere CPI Improper Cert Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41012"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-82456",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj-labs",
      "product": "argocd-mcp",
      "cwe": "CWE-1327",
      "title": "argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82456"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-14494",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "SigmaForms Pro – AI Generated Forms",
      "cwe": "CWE-434",
      "title": "Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14494"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-15369",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Addify",
      "product": "Custom User Registration Fields for WooCommerce",
      "cwe": "CWE-269",
      "title": "Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15369"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-82466",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeremyevans",
      "product": "rodauth",
      "cwe": "CWE-287",
      "title": "Rodauth before 2.46.0 Authentication Bypass via webauthn_login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82466"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-82448",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shinobi Systems",
      "product": "Shinobi",
      "cwe": "CWE-798",
      "title": "Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82448"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-82452",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iot-ecology",
      "product": "rust-iot-platform",
      "cwe": "CWE-306",
      "title": "rust-iot-platform Authentication Bypass via Missing Request Guards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82452"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-82454",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "omnivore-app",
      "product": "omnivore",
      "cwe": "CWE-347",
      "title": "Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82454"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-82460",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coderaiser",
      "product": "cloudcmd",
      "cwe": "CWE-22",
      "title": "Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82460"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-82473",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kubeedge",
      "product": "kubeedge",
      "cwe": "CWE-306",
      "title": "KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82473"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-82447",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Skyvern-AI",
      "product": "skyvern",
      "cwe": "CWE-1336",
      "title": "Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82447"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-82450",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bookstackapp",
      "product": "bookstack",
      "cwe": "CWE-434",
      "title": "BookStack before 26.05.4 Remote Code Execution via Book Cover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82450"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-82453",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iot-ecology",
      "product": "rust-iot-platform",
      "cwe": "CWE-256",
      "title": "rust-iot-platform Cleartext Password Storage via User Model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82453"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-82472",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "documenso",
      "product": "documenso",
      "cwe": "CWE-306",
      "title": "Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82472"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-82481",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mirage",
      "product": "cohttp",
      "cwe": "CWE-180",
      "title": "The cohttp package before 6.3.0 for OCaml allows directory traversal.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82481"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-82461",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pac4j",
      "product": "pac4j",
      "cwe": "CWE-347",
      "title": "pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82461"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-82463",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pac4j",
      "product": "pac4j",
      "cwe": "CWE-863",
      "title": "pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82463"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-82475",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iflytek",
      "product": "astron-agent",
      "cwe": "CWE-862",
      "title": "iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82475"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-82457",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ncopa",
      "product": "su-exec",
      "cwe": "CWE-681",
      "title": "su-exec through 0.3 Privilege Escalation via Numeric User ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82457"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82474",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sudo-project",
      "product": "sudo",
      "cwe": "CWE-693",
      "title": "Sudo through 1.9.17p2 Intercept Policy Bypass via execveat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82474"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-75807",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "SAML Single Sign On – SSO Login",
      "cwe": "CWE-287",
      "title": "SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75807"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-82449",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cockpit-hq",
      "product": "cockpit",
      "cwe": "CWE-208",
      "title": "Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82449"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-82455",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "rubygems",
      "cwe": "CWE-59",
      "title": "RubyGems before 4.0.13 Path Traversal via Symlink Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82455"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-82462",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pac4j",
      "product": "pac4j",
      "cwe": "CWE-345",
      "title": "pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82462"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-82465",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pac4j",
      "product": "pac4j",
      "cwe": "CWE-345",
      "title": "pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82465"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-82476",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usememos",
      "product": "memos",
      "cwe": "CWE-918",
      "title": "Memos through 0.30.0 SSRF via Omitted CGNAT Address Range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82476"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-82417",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ljharb",
      "product": "qs",
      "cwe": "CWE-248",
      "title": "qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82417"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-82562",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ljharb",
      "product": "qs",
      "cwe": "CWE-770",
      "title": "qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82562"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-82477",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MITRE",
      "product": "Heimdall",
      "cwe": "CWE-918",
      "title": "In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82477"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-82451",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getformwork",
      "product": "Formwork",
      "cwe": "CWE-79",
      "title": "Formwork through 2.3.14 Stored XSS via Referer Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82451"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-82464",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pac4j",
      "product": "pac4j",
      "cwe": "CWE-601",
      "title": "pac4j-core before 6.5.6 Open Redirect via Backslash Logout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82464"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-82469",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeremyevans",
      "product": "rodauth",
      "cwe": "CWE-613",
      "title": "Rodauth before 2.47.0 Authentication Bypass via jwt_refresh",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82469"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-82470",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeremyevans",
      "product": "rodauth",
      "cwe": "CWE-294",
      "title": "Rodauth before 2.47.0 TOTP Code Reuse via Drift Window",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82470"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-82467",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeremyevans",
      "product": "rodauth",
      "cwe": "CWE-601",
      "title": "Rodauth before 2.47.0 Open Redirect via Return-to Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82467"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-82468",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeremyevans",
      "product": "rodauth",
      "cwe": "CWE-352",
      "title": "Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82468"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-82364",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macrozheng",
      "product": "mall",
      "cwe": "CWE-362",
      "title": "macrozheng mall Order Submission submit race condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82364"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-82421",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System emp_edit.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82421"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-82422",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Sales and Inventory System",
      "cwe": "CWE-74",
      "title": "itsourcecode Sales and Inventory System emp_del.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82422"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-82423",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macrozheng",
      "product": "mall",
      "cwe": "CWE-840",
      "title": "macrozheng mall Payment Status Endpoint paySuccess behavioral workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82423"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-82424",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPGurukul",
      "product": "Student Information System",
      "cwe": "CWE-74",
      "title": "PHPGurukul Student Information System student_edit1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82424"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10036",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56100",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65053",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65053 (horde imp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71503",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71503 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71504",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71504 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71505",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71505 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71506",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71506 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71507",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71507 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71508",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71508 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71509",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71509 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71510",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71510 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-71511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-71511 (dolibarr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72703 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72704 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72705 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72711",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72711 (leanprover lean4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77939 (flextype). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-78122",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-78122 (Tecnativa docker-socket-proxy). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-60004",
      "detail": "DUE DATE PASSED — CVE-2026-60004 (Gitea). CISA remediation deadline was August 28, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
