Daily briefing · July 10, 2026
Quiet Day Masks Critical Risks: Authentication Bypasses and Injection Flaws Dominate New CVEs
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 10, 2026 registered no actively exploited vulnerabilities and no confirmed in-the-wild exploitation, marking a relatively calm day on the vulnerability front. However, 24 critical CVEs were published, several of them targeting widely deployed platforms such as WordPress plugins, Apache IoTDB, and JetBrains IntelliJ IDEA, carrying CVSS scores up to 9.9. While no exploit tooling has been weaponized yet, the nature of these flaws — authentication bypasses, file uploads, and SQL injection — makes them high-priority targets for rapid armament.
Today’s brief
- No KEV additions today and no actively exploited CVEs, but 24 critical vulnerabilities were published.
- Two Apache IoTDB critical flaws (unsafe reflection + authentication bypass) affect versions from 1.0.0 — upgrade to 2.0.10 immediately.
- Multiple WordPress authentication bypass and file upload CVEs expose sites to unauthenticated account takeover and remote code execution.
- Ransomware group Deadlock claimed multiple Brazilian victims across manufacturing and services sectors in recent days.
Critical highlights
1
A CVSS 9.9 flaw in 9Router allows any unauthenticated user to export or fully overwrite the database — including all credentials, API keys, and OAuth tokens — bypassing only a basic middleware check. The blast radius is severe: a single unauthenticated request can hand attackers the entire secret store of the platform.
2
The Instant Appointment WordPress plugin allows unauthenticated arbitrary file uploads due to missing file type validation, opening the door to remote code execution on any unpatched site running version 1.2 or earlier. The unauthenticated attack surface makes this particularly dangerous for unmonitored WordPress installations.
3
Apache IoTDB's pipe processor instantiates arbitrary Java classes via Class.forName() without any allowlisting, a classic unsafe reflection pattern that enables remote code execution against versions 1.0.0 through pre-2.0.10. Any attacker able to supply input to the pipe processor can execute arbitrary code on the server.
4
Apache IoTDB's REST API accepts stale cached credentials due to insufficient session expiration, enabling capture-replay authentication bypass across all affected versions up to 2.0.10. Combined with CVE-2026-40008, these two IoTDB flaws create a serious compounded risk for IoT infrastructure deployments.
5
CVE-2026-57807CVSS 9.8affects OAuth Single Sign On - SSO (OAuth Client) The miniOrange OAuth Single Sign On plugin for WordPress is vulnerable to authentication bypass via password recovery exploitation, affecting versions through 38.5.8. Attackers could hijack accounts without knowing credentials by abusing the password recovery flow.
6
CVE-2026-12761CVSS 9.8affects miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) The miniOrange Social Login and Register WordPress plugin (through 7.7.0) allows attackers to supply an arbitrary email address during the OAuth profile completion flow, bypassing identity verification and taking over existing accounts. This unauthenticated account takeover path is particularly dangerous on multi-user sites.
7
SEM-PMP, a project management platform, contains a SQL injection vulnerability that can escalate to operating system command execution, affecting all versions through 23042026. This class of flaw — SQL injection leading to command execution — represents one of the most severe attack chains in enterprise software.
8
MobilMen 20T, a retail automation product, is affected by SQL injection from v3 through 10072026, and the vendor has not responded to disclosure attempts. The absence of a vendor patch and the lack of response significantly raises the risk for organizations relying on this product.
9
Prowler's SAML authentication flow trusted attacker-controlled email domains to determine tenant routing, allowing an authenticated attacker to escalate into other tenants' environments — a critical multi-tenancy isolation failure affecting versions prior to 5.30.3. Cloud security teams using Prowler for compliance monitoring should treat this as urgent given the privileged access the platform holds.
10
JetBrains IntelliJ IDEA before versions 2026.1.4 and 2026.2 is vulnerable to code execution via path traversal in project workspace ID handling, a risk that is particularly relevant in CI/CD environments and shared development setups where project files may originate from untrusted sources.
Ransomware today
The Deadlock ransomware group recently claimed multiple Brazilian victims, including Werken Química Brasil S.A., Bombas Ideal, and Direção Estacionamentos S.A., spanning manufacturing and consumer services sectors. The Qilin group also listed S.J. Louis as a victim. Over the past 30 days, the most active groups targeting Brazil include lockbit3 (39 victims), ransomhub (35), and lockbit5 (26), underscoring sustained and aggressive ransomware pressure on Brazilian organizations.
Werken Química Brasil S.A. BRDeadlock · Manufacturing
Bombas Ideal BRDeadlock · Manufacturing
Direção Estacionamentos S.A. BRDeadlock · Consumer Services
S.J. Louis BRqilin
lockbit3 39ransomhub 35lockbit5 26thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated, including againstthewest, apt73, blackshadow (Iran-linked), dragonforce, fulcrumsec, and coinbasecartel — though no specific victims have been attributed to them in the current period. Their presence in threat intelligence feeds warrants monitoring, particularly blackshadow given its Iranian origin and history of targeted destructive operations.
Brazil focus
Brazil continues to face intense ransomware activity, with recent victims spanning multiple sectors: Werken Química Brasil S.A. and Bombas Ideal (Manufacturing, Deadlock), Direção Estacionamentos S.A. (Consumer Services, Deadlock), S.J. Louis (Qilin), tecnocurva.com.br (Technology, incransom), Francisco Imóveis (Consumer Services, Doommageddon), redeplastrs.com.br (Manufacturing, Blackfield), and Service IT (Business Services, worldleaks). The breadth of groups and sectors involved signals that Brazilian organizations of all sizes remain high-value targets for ransomware operators.
Werken Química Brasil S.A.Deadlock · Manufacturing
Direção Estacionamentos S.A.Deadlock · Consumer Services
Bombas IdealDeadlock · Manufacturing
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Francisco ImóveisDoommageddon · Consumer Services
redeplastrs.com.brBlackfield · Manufacturing
Service ITworldleaks · Business Services
Today’s recommendation: Prioritize patching Apache IoTDB to version 2.0.10 and auditing all WordPress installations for the miniOrange and Instant Appointment plugins, applying vendor updates or disabling them immediately if no patch is available. For environments running Prowler or JetBrains IntelliJ IDEA, apply the respective updates and review access logs for any anomalous tenant routing or workspace activity.
With authentication bypasses, file upload flaws, and injection vulnerabilities spanning cloud platforms, developer tools, and CMS plugins, now is the moment to validate which of these affected components are actually present and exposed in your own environment.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →