Daily briefing · August 8, 2026
MSI Router Hit by Eight Critical Command Injection CVEs; WordPress AI Plugin Opens Admin Backdoor
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 8, 2026 brings no active exploitation or weaponized exploits, keeping the day's verdict calm — but the vulnerability disclosures themselves are far from trivial. Eight critical command injection flaws across MSI Radix AXE6600 router firmware and a WordPress plugin flaw enabling unauthenticated admin takeover dominate the landscape, demanding prompt patching even in the absence of confirmed in-the-wild attacks. Defenders should treat the volume and severity of these disclosures as a clear signal to audit exposure now.
Today’s brief
- Eight critical command injection CVEs disclosed in MSI Radix AXE6600 firmware v781521, each enabling remote root access via different router functions
- WordPress AI Copilot plugin flaw (CVSS 9.8) allows unauthenticated attackers to create administrator accounts and fully take over sites
- No active exploitation (KEV) or weaponized exploits confirmed today — but severity warrants immediate patching
- Brazil faces active ransomware pressure, with government, education, and technology sectors hit recently by multiple groups
Critical highlights
1
An authorization bypass in the AI Copilot – Content Generator WordPress plugin (all versions through 1.5.6) lets any unauthenticated attacker create a new administrator account and achieve complete site takeover — the highest practical risk for WordPress site owners who haven't updated.
2
A command injection in the MSI Radix AXE6600 openvpn function allows remote attackers to execute arbitrary commands and gain root privileges on the router — one of eight critical flaws in the same firmware version that collectively expose the device across multiple attack surfaces.
3
The macfilter function in MSI Radix AXE6600 firmware v781521 is vulnerable to command injection, enabling remote root-level code execution; attackers can chain this with other disclosed flaws across the same device for maximum impact.
4
A command injection in the TelnetSSH function (Telnet configuration path) of MSI Radix AXE6600 allows remote attackers to inject and execute arbitrary commands, escalating to root — particularly risky if the Telnet interface is exposed to untrusted networks.
5
The SSH configuration path of the TelnetSSH function in MSI Radix AXE6600 carries an independent command injection vulnerability, granting remote root access through the SSH management interface without requiring prior authentication context.
6
The porTrigger function in MSI Radix AXE6600 firmware is vulnerable to command injection exploitable via the ALG interface, allowing remote attackers to obtain root privileges — another entry point in a router that is now mapped across eight critical weaknesses.
7
Command injection in the portFw (port forwarding) function of MSI Radix AXE6600 enables remote arbitrary command execution at root level, expanding the attack surface for anyone with network access to the device's management plane.
8
The alg function itself in MSI Radix AXE6600 is directly injectable, allowing root-level command execution; the repeated appearance of the ALG subsystem across multiple CVEs suggests a systemic input validation failure in this firmware branch.
9
A command injection flaw in the dmz function of MSI Radix AXE6600 firmware v781521 lets remote attackers execute arbitrary commands and gain root privileges, adding yet another exploitable path to an already heavily exposed device.
10
The accesscontrol function in MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability enabling remote root access — completing a set of eight critical flaws that, taken together, make this firmware version effectively indefensible without an urgent update.
Ransomware today
Several Brazilian organizations have been recently claimed as ransomware victims across multiple groups: thegentlemen targeted Intranet Gov Brasil (government sector), ransomhouse hit Alya Construtora (manufacturing), L Group claimed brdigital.net.br and uva.edu.br (technology and education), and spacebears listed PontoBR Sistemas (technology). Over the past 30 days, lockbit5 has been the most prolific actor with 24 victims, all in Brazil, followed by Section9 (6), Global Secret Group (4), and Deadlock (3).
Intranet Gov Brasil BRthegentlemen · Government & Defense
Alya Construtora BRransomhouse · Manufacturing
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
lockbit5 24Section9 6Global Secret Group 4Deadlock 3thegentlemen 3L Group 2
Active groups & APTs
Several threat actor groups — including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — have been flagged as active or recently updated, though no confirmed victims are attributed to them at this time. Their presence in threat intelligence feeds warrants monitoring, as low victim counts may reflect early-stage operations or unreported activity rather than inactivity.
Brazil focus
Brazil is under sustained ransomware pressure across critical sectors: recent victims include a government network (Intranet Gov Brasil), two educational institutions (uva.edu.br and cesmac.edu.br), and multiple technology companies (brdigital.net.br, PontoBR Sistemas, eSysTech). Groups such as lockbit5, L Group, krybit, Orova, and thegentlemen have all claimed Brazilian targets in the past 30 days, underscoring that no sector is outside the current targeting scope.
Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Organizations running MSI Radix AXE6600 routers should apply firmware updates immediately and restrict management interfaces to trusted networks; WordPress administrators should update the AI Copilot – Content Generator plugin to a patched version and audit for any unauthorized administrator accounts.
Even on a calm disclosure day, the breadth and severity of today's findings underscore why continuously validating your own attack surface — before threat actors do — is the only reliable defensive posture.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
August 7, 2026 — Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under FireAugust 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New Exploitsview full archive →