Daily briefing · July 8, 2026
WordPress and CoreWCF Under Pressure: Active Exploitation Detected on July 8, 2026
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
July 8, 2026 brings a wave of 335 new vulnerabilities, including 18 rated critical, with one standing out as already observed in active exploitation by VulnCheck ahead of any official CISA confirmation — a WordPress plugin flaw enabling unauthenticated file uploads. The day's verdict is CAUTION: no fully weaponized exploits confirmed, but the early exploitation signal on Blocksy Companion and a CVSS 10.0 authentication bypass in CoreWCF demand immediate defensive attention. Defenders should treat the VulnCheck-flagged CVE as actively weaponized in practice, regardless of official KEV status.
Today’s brief
- CVE-2026-58480 (Blocksy Companion, WordPress): unauthenticated file upload already observed in exploitation by VulnCheck — patch or disable now.
- CVE-2026-54782 (CoreWCF): CVSS 10.0 SAML token validation bypass allows full identity impersonation without authentication — maximum severity.
- CVE-2026-12153 (WP Learn Manager) and CVE-2026-9701 (Eventer): two additional critical WordPress plugin flaws enabling unauthorized plugin installs and account takeover.
- Brazil-focused ransomware activity is intensifying, with victims claimed by qilin, incransom, and Doommageddon across multiple sectors.
Critical highlights
1
VulnCheck has observed exploitation of this flaw in Blocksy Companion Pro (WordPress, before 2.1.47) before CISA's official acknowledgment — a strong early warning signal. Unauthenticated attackers can bypass extension validation via a double-extension trick in the Custom Fonts/Advanced Reviews feature to upload executable files, enabling remote code execution on any exposed WordPress site.
2
A CVSS 10.0 critical flaw in CoreWCF (before 1.8.1/1.9.1) allows an unauthenticated remote attacker to completely bypass SAML 1.1 and 2.0 token validation when federated bindings are used, effectively impersonating any principal the trusted STS can issue — this means full identity takeover with zero credentials on vulnerable .NET Core services.
3
WP Learn Manager (WordPress, up to 1.1.8) fails to verify user authorization, allowing completely unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository — a trivial path to full site compromise via a malicious or vulnerable third-party plugin.
4
An improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (releases 2020 through 2026) could grant an attacker privileged server access — particularly concerning in manufacturing and industrial environments where this MES platform is commonly deployed.
5
The Eventer WordPress plugin (up to 4.4.2) stores password reset keys in plaintext in the wp_usermeta table, enabling any user with database read access or exploiting a secondary SQLi to trivially reset any account's password and take over the site.
6
Fluentd (before 1.19.3) allows path traversal through insufficient validation of the ${tag} placeholder in file output plugin configurations, enabling attackers who can control log tag values to write files to arbitrary paths on the server — a serious risk in centralized logging pipelines.
7
A classic SQL injection in Mediküm Web (Webbeyaz) through version 08072026 allows arbitrary database manipulation — compounded by the fact that the vendor has confirmed the product is no longer supported, meaning no patch will be issued and exposed instances must be isolated or decommissioned immediately.
8
Authenticated low-privilege users of the Snowflake Snowpark Python SDK (before 1.53.0) can escalate privileges by injecting SQL payloads through specially crafted column names in the DataFrameReader.dbapi() API — a privilege escalation path that could expose sensitive data warehousing infrastructure.
9
A cross-site scripting vulnerability in Microsoft Dynamics 365 Customer Voice enables network-based spoofing attacks against unauthenticated targets — a risk for organizations relying on this platform for customer feedback and survey workflows, where session or credential theft via crafted links is plausible.
10
JupyterLab Git (0.30.0b3 to 0.53.x) passes Git filenames directly to innerHTML when rendering renamed files in commit history, meaning a maliciously crafted filename in a repository can execute arbitrary JavaScript in any victim's browser viewing the Git History tab — a stored XSS risk in widely used data science environments.
Ransomware today
Ransomware activity targeting Brazilian organizations remains at elevated levels. Recently claimed victims include S.J. Louis (qilin), tecnocurva.com.br in the Technology sector (incransom), and Francisco Imóveis in Consumer Services (Doommageddon). Over the past 30 days, lockbit3, ransomhub, and lockbit5 have been the most prolific groups, with lockbit3 accounting for 39 victims in Brazil alone.
S.J. Louis BRqilin
tecnocurva.com.br BRincransom · Technology
Francisco Imóveis BRDoommageddon · Consumer Services
lockbit3 39ransomhub 35lockbit5 26thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors are currently being tracked with updated activity profiles, including againstthewest, apt73, dragonforce, fulcrumsec, coinbasecartel, and Iran-linked blackshadow. While no new confirmed victims are attributed to these groups in this cycle, their active monitoring status suggests operational readiness, and apt73 has been linked to a recent victim in Brazil (flazio.com).
Brazil focus
Brazil continues to be a heavily targeted country in the current ransomware landscape. Recent victims span multiple sectors: S.J. Louis (qilin), tecnocurva.com.br (incransom, Technology), Francisco Imóveis (Doommageddon, Consumer Services), redeplastrs.com.br (Blackfield, Manufacturing), Service IT (worldleaks, Business Services), tambasa.com and carvalima.com.br (both incransom, Business Services). The concentration of incransom activity against Brazilian targets is particularly notable.
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Francisco ImóveisDoommageddon · Consumer Services
redeplastrs.com.brBlackfield · Manufacturing
flazio.comapt73 · Technology
Service ITworldleaks · Business Services
tambasa.comincransom
carvalima.com.brincransom · Business Services
Today’s recommendation: Immediately patch or disable the Blocksy Companion Pro plugin on all WordPress installations given active exploitation observed in the wild, and prioritize updating CoreWCF to 1.8.1 or 1.9.1 in any .NET Core service using federated SAML bindings. Organizations running other affected WordPress plugins (WP Learn Manager, Eventer) and Fluentd should also treat those updates as urgent given the unauthenticated attack surface exposed.
The breadth of today's critical vulnerabilities — spanning CMS plugins, logging pipelines, data platforms, and enterprise identity — underscores why validating your actual exposed attack surface, rather than relying on vendor advisory timelines alone, is essential to understanding real organizational risk.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →