Daily briefing · July 15, 2026

Ten Critical CVEs Disclosed on a Calm Day: Open-Source Tools Dominate the Risk Landscape

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 15, 2026 brought no active exploitation or weaponized vulnerabilities, but the disclosure volume was far from trivial — 260 new CVEs were published, 28 of them critical, with ten high-severity findings concentrated in widely used open-source platforms. The calm verdict reflects the absence of confirmed in-the-wild exploitation, not a lack of severity: several of the disclosed flaws carry CVSS 10.0 scores and functional exploits, meaning the window for defenders to act before attackers is open but not unlimited.

Today’s brief
  • No active exploitation confirmed today, but 28 critical CVEs were published — a deceptively calm day with high latent risk.
  • Four CVSS 10.0 vulnerabilities disclosed across 9Router, NocoBase, Metabase, and Wazuh — all requiring immediate patching.
  • CVE-2026-46339 (9Router) ships with a functional exploit already available, the closest thing to a ready weapon in today's batch.
  • Brazil remains under sustained ransomware pressure, with LockBit5 and Deadlock actively claiming Brazilian victims across multiple sectors.
28
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-46339CVSS 10Functional exploitaffects 9router
A CVSS 10.0 flaw in 9Router with a functional exploit already available — unauthenticated attackers can register custom plugins and achieve remote command execution through an unprotected API middleware. Organizations running versions 0.4.30 through 0.4.36 should treat this as the most urgent patch of the day.
2
CVE-2026-52887CVSS 10affects nocobase
NocoBase's in-app notification API inserted user-supplied filter parameters directly into a Sequelize.literal() template without sanitization, enabling SQL injection by any authenticated user. With CVSS 10.0 and no-code platforms increasingly used to store sensitive business data, exploitation here could expose entire datasets.
3
CVE-2026-50148CVSS 10affects metabase
A CVSS 10.0 RCE in Metabase allows any user with database connection permissions to achieve remote code execution on the server by pointing a Snowflake connection to an attacker-controlled endpoint, exploiting a flaw in the Snowflake JDBC driver. Metabase deployments where non-admin users can manage connections are directly at risk.
4
CVE-2026-56699CVSS 10affects wazuh
Wazuh Manager before 5.0.0-beta3 fails to escape a field in OpenSearch bulk requests, letting enrolled agents inject arbitrary NDJSON operations — including deleting alerts or tampering with SIEM state — under admin credentials. This is particularly dangerous because it undermines the integrity of the very tool used to detect threats.
5
CVE-2026-52891CVSS 9.9affects wekan
Wekan's avatar upload feature passes user-supplied filenames to a shell command without sanitization, allowing any user to execute arbitrary OS commands on the server via shell metacharacters. With CVSS 9.9, this is a straightforward path to full server compromise on unpatched instances.
6
CVE-2026-54052CVSS 9.9affects n8n-mcp
In n8n-MCP's multi-tenant HTTP mode, workflow version history backups were not isolated per tenant, allowing authenticated users to read or destroy workflow snapshots belonging to other tenants. This is a critical data isolation failure in an AI-automation context where workflows may contain credentials and sensitive logic.
7
CVE-2026-44986CVSS 9.9affects penpot
Penpot's invitation and registration flow allowed a registered user to take over another account by exploiting a token leak and a session issuance path that skipped password verification. Account takeover at CVSS 9.9 in a collaborative design tool means exposure of all shared project assets and team membership data.
8
CVE-2026-55652CVSS 9.8affects wekan
Wekan's header-login mechanism trusted the client-supplied X-Forwarded-For header over the actual socket address, enabling an unauthenticated attacker to impersonate any user — including admins — simply by crafting the right HTTP header. This is a trivial-to-exploit authentication bypass that should be patched or mitigated immediately.
9
CVE-2026-49352CVSS 9.8PoCaffects 9router
9Router used a hardcoded fallback JWT secret ('9router-default-secret-change-me') when JWT_SECRET was unset, allowing any attacker to forge valid authentication cookies. A proof-of-concept is available, and the predictability of the secret makes this trivially exploitable against misconfigured deployments.
10
CVE-2026-54458CVSS 9.6affects AVideo
A stored DOM XSS in AVideo's YPTSocket plugin allows unauthenticated attackers to inject JavaScript that executes in the browser of any administrator viewing the affected debug panel. Successful exploitation could lead to session hijacking or privilege escalation against platform administrators.
Ransomware today

LockBit5 recently claimed sweetome.com, a Brazilian consumer services company, adding to a growing list of Brazilian victims attributed to the group. Over the past 30 days, the most active ransomware groups have included lockbit3, ransomhub, lockbit5, thegentlemen, 8base, and arcusmedia, all of which have registered activity in Brazil — a sign that the country remains a prioritized target across the full threat spectrum.

sweetome.com BRlockbit5 · Consumer Services
lockbit3 39ransomhub 35lockbit5 30thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors are being tracked as active or updated, including apt73, blackshadow (Iran), coinbasecartel, CopyKittens (Iran), dragonforce, and againstthewest. While no confirmed victims are currently attributed to these groups in the latest data, their active tracking status indicates ongoing operational posture that defenders — particularly those in sectors historically targeted by Iranian-linked actors — should monitor closely.

Brazil focus

Brazil is experiencing sustained ransomware pressure across multiple sectors: LockBit5 has claimed sweetome.com (consumer services), saude.mt.gov.br (public sector), lbreng.com.br, and santoinacio-rio.com.br (business services) in recent weeks. The Deadlock group has targeted Bombas Ideal and Werken Química Brasil S.A. (manufacturing) as well as Direção Estacionamentos S.A. (consumer services), while Qilin claimed S.J. Louis. The breadth of sectors affected — from government health portals to industrial manufacturers — underscores that no vertical in Brazil is out of scope.

sweetome.comlockbit5 · Consumer Services
saude.mt.gov.brlockbit5 · Public Sector
lbreng.com.brlockbit5 · Business Services
santoinacio-rio.com.brlockbit5 · Business Services
Bombas IdealDeadlock · Manufacturing
Werken Química Brasil S.A.Deadlock · Manufacturing
Direção Estacionamentos S.A.Deadlock · Consumer Services
S.J. Louisqilin
Today’s recommendation: Prioritize patching CVE-2026-46339 and CVE-2026-55652 in 9Router and Wekan respectively, as both combine critical severity with available exploit code or trivial attack mechanics. Audit all open-source self-hosted platforms in your environment against today's disclosure list and verify that JWT secrets, authentication headers, and API middleware are properly configured before attackers weaponize the remaining findings.
Even on a calm day with no confirmed exploitation, today's disclosures are a reminder that the gap between 'published' and 'weaponized' can close within hours — validating your own attack surface against these specific product versions is the only way to know whether you are exposed before threat actors do.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →