Daily briefing · July 12, 2026

Quiet CVE Day Masks Active Ransomware Wave Targeting Brazil

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 12, 2026 registered a calm day on the vulnerability front, with 73 new CVEs published, three rated critical, and zero confirmed active exploitation or weaponized exploits. Still, the ten highlighted vulnerabilities carry serious practical risk — spanning XSS injection in router admin panels, hardcoded JWT secrets, and command injection in network devices — and defenders should not let the quiet CVSS headline distract from the urgent ransomware activity hitting Brazilian organizations.

Today’s brief
  • 3 critical CVEs published today, none yet confirmed exploited in the wild — but two carry public proof-of-concept code
  • LuCI (OpenWrt) affected by two flaws: stored XSS via UPnP and DHCPv6 hostname injection, both targeting admin browser sessions
  • Flowise hardcoded JWT secrets (CVE-2026-56271) allow authentication bypass on any default-config deployment
  • Brazil under active ransomware pressure: LockBit5 and Deadlock claimed at least 6 Brazilian victims in recent days, including a state health secretariat
3
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-61876CVSS 9.4affects luci
Adjacent network attackers can inject script tags via malformed DHCPv6 FQDN hostnames, executing arbitrary JavaScript in the administrator's browser when the DHCP lease table is viewed — a stealthy attack vector that requires no authentication beyond LAN access.
2
CVE-2026-15511CVSS 9.3PoCaffects CF-WR631AX V3
A publicly disclosed command injection flaw in the Comfast CF-WR631AX V3 FastCGI backend allows remote attackers to execute OS commands by manipulating the filename argument — the public exploit availability makes patching or isolation urgent.
3
CVE-2026-56271CVSS 9.3affects Flowise
Flowise versions up to 3.0.13 ship with weak hardcoded JWT secrets ('auth_token', 'refresh_token') and default audience/issuer values, meaning any attacker who knows the defaults — which are now public — can forge valid authentication tokens on unmodified deployments.
4
CVE-2026-56260HIGH 8.8affects Crawl4AI
Crawl4AI's Docker API server accepts arbitrary filesystem paths in the output_path parameter of its /screenshot and /pdf endpoints, enabling remote attackers to overwrite critical server files and trigger denial of service without authentication.
5
CVE-2026-56259HIGH 8.8affects Crawl4AI
A companion flaw in Crawl4AI allows unauthenticated attackers to redirect LLM API calls to attacker-controlled endpoints and exfiltrate environment variables — including provider API keys — by abusing the base_url and api_token parameters on several open endpoints.
6
CVE-2026-15481HIGH 8.7PoCaffects TEW-635BRM
Command injection in the IPoA WAN connection setup of TRENDnet TEW-635BRM (up to 1.00.03) is remotely exploitable and has a publicly available proof-of-concept — this end-of-life device is unlikely to receive a patch, making network segmentation the primary mitigation.
7
CVE-2026-15484HIGH 8.7affects TEW-821DAP
A buffer overflow in the nslookup handler of TRENDnet TEW-821DAP 1.12B01 can be triggered remotely; the vendor acknowledges the device is EOL and will not issue a fix, leaving deployment isolation as the only realistic defense.
8
CVE-2026-15483HIGH 8.7affects TEW-821DAP
A second buffer overflow variant in the same nslookup component of TEW-821DAP, triggered via the nslookup_target argument — the combination of two remotely exploitable overflows on an EOL device with no vendor support significantly raises the effective risk.
9
CVE-2026-15480HIGH 8.7PoCaffects TEW-635BRM
A stack-based buffer overflow in the Web Service component of TRENDnet TEW-635BRM, manipulated via the device_name argument, is remotely exploitable with a public exploit already available — any internet-exposed instance should be considered compromised until isolated.
10
CVE-2026-61875HIGH 8.7affects luci
LuCI's UPnP application renders miniupnpd port-mapping descriptions without output encoding, letting any unauthenticated LAN client plant persistent JavaScript that executes in the admin's browser — a low-barrier stored XSS that could lead to full router compromise.
Ransomware today

LockBit5 and Deadlock have been particularly active against Brazilian targets in recent days. LockBit5 claimed three victims: lbreng.com.br and santoinacio-rio.com.br (both in Business Services) and saude.mt.gov.br, the health secretariat of Mato Grosso state — a critical public sector target. Deadlock struck manufacturing and consumer services with Werken Química Brasil S.A., Bombas Ideal, and Direção Estacionamentos S.A. Among the top groups active over the last 30 days, lockbit3, ransomhub, lockbit5, thegentlemen, 8base, and arcusmedia all show concentrated activity in Brazil.

santoinacio-rio.com.br BRlockbit5 · Business Services
lbreng.com.br BRlockbit5 · Business Services
saude.mt.gov.br BRlockbit5 · Public Sector
Werken Química Brasil S.A. BRDeadlock · Manufacturing
Bombas Ideal BRDeadlock · Manufacturing
Direção Estacionamentos S.A. BRDeadlock · Consumer Services
lockbit3 39ransomhub 35lockbit5 29thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors are being tracked as currently active or recently updated: apt73, BlackShadow (Iran), CoinbaseCartel, CopyKittens (Iran), DragonForce, and AgainstTheWest. No confirmed victims have been attributed to these groups in the current period, but their presence in threat intelligence feeds signals that their infrastructure or tooling is active — organizations in relevant verticals should monitor for indicators associated with these actors.

Brazil focus

Brazil is facing a concentrated ransomware campaign with at least eight organizations victimized across multiple sectors in recent weeks, spanning public administration, manufacturing, business services, consumer services, and technology. Beyond the LockBit5 and Deadlock clusters, qilin claimed S.J. Louis and incransom targeted tecnocurva.com.br, illustrating that the threat is not limited to a single group. The compromise of saude.mt.gov.br is particularly significant given the sensitivity of health data and potential disruption to public services.

lbreng.com.brlockbit5 · Business Services
santoinacio-rio.com.brlockbit5 · Business Services
saude.mt.gov.brlockbit5 · Public Sector
Direção Estacionamentos S.A.Deadlock · Consumer Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Today’s recommendation: Prioritize patching or isolating Flowise deployments running default JWT configurations (CVE-2026-56271) and restrict LAN-side access to LuCI admin interfaces on OpenWrt routers to mitigate the XSS injection risks; for EOL TRENDnet devices with no available patch, network segmentation or decommissioning is the only reliable control.
Even on a relatively quiet vulnerability day, the combination of newly published proof-of-concept exploits and active ransomware targeting Brazilian organizations is a strong reminder to continuously validate your own external and internal attack surface — knowing what is exposed is the first step before any patch or control can be effective.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →