Daily briefing · July 16, 2026

Jupyter and WordPress Flaws Dominate a Calm but CVE-Heavy Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 16, 2026 saw no actively exploited vulnerabilities and no weaponized proof-of-concept code confirmed in the wild, making it a relatively calm day despite 263 new CVEs published, 33 of them critical. The spotlight falls on a trio of perfect-score flaws in Jupyter Enterprise Gateway and a cluster of authentication-bypass issues targeting WordPress plugins. While the threat landscape at the CVE level stays at a monitoring posture, ransomware activity against Brazilian organizations tells a very different story.

Today’s brief
  • No CVEs in active exploitation (KEV) and no ready-made exploit modules confirmed today — monitoring posture applies.
  • Three CVSS 10.0 flaws hit Jupyter Enterprise Gateway: YAML injection, SSTI, and root UID bypass — patch to 3.3.0 immediately.
  • WordPress ecosystem takes multiple critical hits: authentication bypass in OTP Login, SAML SSO, and privilege escalation in Bricksforge.
  • Brazil is under heavy ransomware pressure, with LockBit5 and RansomHouse hitting education, services, and technology sectors.
33
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-44182CVSS 10affects enterprise_gateway
A CVSS 10.0 YAML injection flaw in Jupyter Enterprise Gateway (before 3.3.0) allows attackers to manipulate untrusted KERNEL_XXX environment variables that are interpolated into Kubernetes manifests without proper escaping, potentially enabling full cluster compromise.
2
CVE-2026-44181CVSS 10affects enterprise_gateway
Also scoring CVSS 10.0, this Server-Side Template Injection vulnerability in Jupyter Enterprise Gateway allows Jinja2 template expressions embedded in KERNEL_XXX variables to be rendered server-side, enabling remote code execution in versions 2.0.0rc2 through 3.2.x.
3
CVE-2026-45336CVSS 10affects HireFlow
HireFlow 1.2 and earlier ships with a hard-coded Flask secret key in its public source code, letting any unauthenticated attacker forge session cookies with admin privileges — a textbook credential bypass with zero barrier to exploitation.
4
CVE-2026-46512CVSS 9.9affects frogman
Frogman's headless PBX component (before 1.6.2) allows a PERM_WRITE-privileged caller to inject arbitrary Asterisk dialplan configuration via unsanitized template parameters, potentially enabling unauthorized call routing or system-level abuse.
5
CVE-2026-45568CVSS 9.9affects zrok
zrok's Python SDK (before 2.0.3) contains a Server-Side Request Forgery flaw where an attacker-controlled URL in the request path can override the configured proxy target, causing the backend to fetch and return arbitrary remote content.
6
CVE-2026-15013CVSS 9.8affects SAML Single Sign On – SSO Login
The SAML Single Sign On – SSO Login WordPress plugin (through 5.4.3) is vulnerable to authentication bypass via Signature Algorithm Confusion, as it reads the signing algorithm from attacker-controlled SAML response data rather than enforcing a locally configured value.
7
CVE-2026-12492CVSS 9.8PoCaffects Happy Coders OTP Login for WooCommerce
The Happy Coders OTP Login for WooCommerce plugin (before 2.8) skips actual OTP validation before authenticating users, allowing unauthenticated attackers to log in as any user including administrators — a proof-of-concept is already available, raising the urgency.
8
CVE-2026-14956CVSS 9.8affects Bricksforge
Bricksforge for WordPress (through 3.1.8.6) allows unauthenticated attackers to escalate to administrator by abusing improper validation of field IDs in the Pro Forms registration flow, enabling full site takeover without credentials.
9
CVE-2026-44180CVSS 9.8affects enterprise_gateway
A third critical flaw in Jupyter Enterprise Gateway allows bypassing the prohibited UID/GID 0 restriction through a specially crafted KERNEL_UID or KERNEL_GID value, potentially launching Kubernetes kernels as root and undermining cluster isolation.
10
CVE-2026-53412CVSS 9.8affects Zoom Workplace for Windows
Improper input validation in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows may allow an unauthenticated network attacker to perform account takeover — a high-impact flaw given Zoom's ubiquity in enterprise environments.
Ransomware today

Ransomware activity against Brazilian organizations has been intense in recent days, with LockBit5 claiming the largest share of victims including educational institutions sesi.org.br, senai.br, and cmc.com.br, alongside business services firms aditusbr.com, montaury.com.br, and consumer-facing drogales.com.br and sweetome.com. RansomHouse added Megawork to its list, while the group Settra claimed acilab.com in the technology sector. Over the past 30 days, LockBit3, LockBit5, and RansomHub have each exceeded 35 confirmed victims in Brazil alone, reflecting a sustained and focused campaign against the country.

cmc.com.br BRlockbit5 · Education
acilab.com BRsettra · Technology
Megawork BRransomhouse · Business Services
sesi.org.br BRlockbit5 · Education
senai.br BRlockbit5 · Education
aditusbr.com BRlockbit5 · Business Services
drogales.com.br BRlockbit5 · Consumer Services
montaury.com.br BRlockbit5 · Business Services
sweetome.com BRlockbit5 · Consumer Services
lockbit3 39lockbit5 36ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actor groups are currently tracked as active or recently updated, including Iranian-linked actors BlackShadow and CopyKittens, along with APT73, DragonForce, AgainstTheWest, and CoinbaseCartel. While no confirmed new victims are attributed to these groups in the current reporting window, their continued operational tracking signals maintained capability and potential for near-term activity.

Brazil focus

Brazil remains one of the most heavily targeted countries in the current ransomware landscape, with LockBit5 alone claiming multiple victims across education and business services sectors in recent days. The breadth of targets — ranging from professional training bodies like SENAI and SESI to small businesses and consumer services — indicates opportunistic as well as strategic targeting. Security teams in Brazilian organizations should treat ransomware exposure as an active and immediate threat, not a theoretical risk.

montaury.com.brlockbit5 · Business Services
drogales.com.brlockbit5 · Consumer Services
senai.brlockbit5 · Education
Megaworkransomhouse · Business Services
sesi.org.brlockbit5 · Education
aditusbr.comlockbit5 · Business Services
acilab.comsettra · Technology
cmc.com.brlockbit5 · Education
Today’s recommendation: Organizations running Jupyter Enterprise Gateway should upgrade to 3.3.0 immediately to address three separate CVSS 10.0 flaws; WordPress administrators should audit and patch the SAML SSO, OTP Login, and Bricksforge plugins without delay, prioritizing sites where unauthenticated registration or login is enabled.
Given the breadth of critical flaws published today — spanning cluster orchestration platforms, SSO systems, and widely deployed CMS plugins — now is the right moment to validate your own attack surface and confirm whether any of these components are reachable from untrusted networks.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share