Daily briefing · August 8, 2026

MSI Router Hit by Eight Critical Command Injection CVEs; WordPress AI Plugin Opens Admin Backdoor

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 8, 2026 brings no active exploitation or weaponized exploits, keeping the day's verdict calm — but the vulnerability disclosures themselves are far from trivial. Eight critical command injection flaws across MSI Radix AXE6600 router firmware and a WordPress plugin flaw enabling unauthenticated admin takeover dominate the landscape, demanding prompt patching even in the absence of confirmed in-the-wild attacks. Defenders should treat the volume and severity of these disclosures as a clear signal to audit exposure now.

Today’s brief
  • Eight critical command injection CVEs disclosed in MSI Radix AXE6600 firmware v781521, each enabling remote root access via different router functions
  • WordPress AI Copilot plugin flaw (CVSS 9.8) allows unauthenticated attackers to create administrator accounts and fully take over sites
  • No active exploitation (KEV) or weaponized exploits confirmed today — but severity warrants immediate patching
  • Brazil faces active ransomware pressure, with government, education, and technology sectors hit recently by multiple groups
27
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-14526CVSS 9.8affects AI Copilot – Content Generator
An authorization bypass in the AI Copilot – Content Generator WordPress plugin (all versions through 1.5.6) lets any unauthenticated attacker create a new administrator account and achieve complete site takeover — the highest practical risk for WordPress site owners who haven't updated.
2
CVE-2026-71993CVSS 9.3affects Radix AXE6600
A command injection in the MSI Radix AXE6600 openvpn function allows remote attackers to execute arbitrary commands and gain root privileges on the router — one of eight critical flaws in the same firmware version that collectively expose the device across multiple attack surfaces.
3
CVE-2026-71992CVSS 9.3affects Radix AXE6600
The macfilter function in MSI Radix AXE6600 firmware v781521 is vulnerable to command injection, enabling remote root-level code execution; attackers can chain this with other disclosed flaws across the same device for maximum impact.
4
CVE-2026-71991CVSS 9.3affects Radix AXE6600
A command injection in the TelnetSSH function (Telnet configuration path) of MSI Radix AXE6600 allows remote attackers to inject and execute arbitrary commands, escalating to root — particularly risky if the Telnet interface is exposed to untrusted networks.
5
CVE-2026-71990CVSS 9.3affects Radix AXE6600
The SSH configuration path of the TelnetSSH function in MSI Radix AXE6600 carries an independent command injection vulnerability, granting remote root access through the SSH management interface without requiring prior authentication context.
6
CVE-2026-71989CVSS 9.3affects Radix AXE6600
The porTrigger function in MSI Radix AXE6600 firmware is vulnerable to command injection exploitable via the ALG interface, allowing remote attackers to obtain root privileges — another entry point in a router that is now mapped across eight critical weaknesses.
7
CVE-2026-71988CVSS 9.3affects Radix AXE6600
Command injection in the portFw (port forwarding) function of MSI Radix AXE6600 enables remote arbitrary command execution at root level, expanding the attack surface for anyone with network access to the device's management plane.
8
CVE-2026-71987CVSS 9.3affects Radix AXE6600
The alg function itself in MSI Radix AXE6600 is directly injectable, allowing root-level command execution; the repeated appearance of the ALG subsystem across multiple CVEs suggests a systemic input validation failure in this firmware branch.
9
CVE-2026-71986CVSS 9.3affects Radix AXE6600
A command injection flaw in the dmz function of MSI Radix AXE6600 firmware v781521 lets remote attackers execute arbitrary commands and gain root privileges, adding yet another exploitable path to an already heavily exposed device.
10
CVE-2026-71985CVSS 9.3affects Radix AXE6600
The accesscontrol function in MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability enabling remote root access — completing a set of eight critical flaws that, taken together, make this firmware version effectively indefensible without an urgent update.
Ransomware today

Several Brazilian organizations have been recently claimed as ransomware victims across multiple groups: thegentlemen targeted Intranet Gov Brasil (government sector), ransomhouse hit Alya Construtora (manufacturing), L Group claimed brdigital.net.br and uva.edu.br (technology and education), and spacebears listed PontoBR Sistemas (technology). Over the past 30 days, lockbit5 has been the most prolific actor with 24 victims, all in Brazil, followed by Section9 (6), Global Secret Group (4), and Deadlock (3).

Intranet Gov Brasil BRthegentlemen · Government & Defense
Alya Construtora BRransomhouse · Manufacturing
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
lockbit5 24Section9 6Global Secret Group 4Deadlock 3thegentlemen 3L Group 2
Active groups & APTs

Several threat actor groups — including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — have been flagged as active or recently updated, though no confirmed victims are attributed to them at this time. Their presence in threat intelligence feeds warrants monitoring, as low victim counts may reflect early-stage operations or unreported activity rather than inactivity.

Brazil focus

Brazil is under sustained ransomware pressure across critical sectors: recent victims include a government network (Intranet Gov Brasil), two educational institutions (uva.edu.br and cesmac.edu.br), and multiple technology companies (brdigital.net.br, PontoBR Sistemas, eSysTech). Groups such as lockbit5, L Group, krybit, Orova, and thegentlemen have all claimed Brazilian targets in the past 30 days, underscoring that no sector is outside the current targeting scope.

Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Organizations running MSI Radix AXE6600 routers should apply firmware updates immediately and restrict management interfaces to trusted networks; WordPress administrators should update the AI Copilot – Content Generator plugin to a patched version and audit for any unauthorized administrator accounts.
Even on a calm disclosure day, the breadth and severity of today's findings underscore why continuously validating your own attack surface — before threat actors do — is the only reliable defensive posture.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 7, 2026Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under FireAugust 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New Exploitsview full archive →