Daily briefing · July 16, 2026
Jupyter and WordPress Flaws Dominate a Calm but CVE-Heavy Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 16, 2026 saw no actively exploited vulnerabilities and no weaponized proof-of-concept code confirmed in the wild, making it a relatively calm day despite 263 new CVEs published, 33 of them critical. The spotlight falls on a trio of perfect-score flaws in Jupyter Enterprise Gateway and a cluster of authentication-bypass issues targeting WordPress plugins. While the threat landscape at the CVE level stays at a monitoring posture, ransomware activity against Brazilian organizations tells a very different story.
Today’s brief
- No CVEs in active exploitation (KEV) and no ready-made exploit modules confirmed today — monitoring posture applies.
- Three CVSS 10.0 flaws hit Jupyter Enterprise Gateway: YAML injection, SSTI, and root UID bypass — patch to 3.3.0 immediately.
- WordPress ecosystem takes multiple critical hits: authentication bypass in OTP Login, SAML SSO, and privilege escalation in Bricksforge.
- Brazil is under heavy ransomware pressure, with LockBit5 and RansomHouse hitting education, services, and technology sectors.
Critical highlights
1
A CVSS 10.0 YAML injection flaw in Jupyter Enterprise Gateway (before 3.3.0) allows attackers to manipulate untrusted KERNEL_XXX environment variables that are interpolated into Kubernetes manifests without proper escaping, potentially enabling full cluster compromise.
2
Also scoring CVSS 10.0, this Server-Side Template Injection vulnerability in Jupyter Enterprise Gateway allows Jinja2 template expressions embedded in KERNEL_XXX variables to be rendered server-side, enabling remote code execution in versions 2.0.0rc2 through 3.2.x.
3
HireFlow 1.2 and earlier ships with a hard-coded Flask secret key in its public source code, letting any unauthenticated attacker forge session cookies with admin privileges — a textbook credential bypass with zero barrier to exploitation.
4
Frogman's headless PBX component (before 1.6.2) allows a PERM_WRITE-privileged caller to inject arbitrary Asterisk dialplan configuration via unsanitized template parameters, potentially enabling unauthorized call routing or system-level abuse.
5
zrok's Python SDK (before 2.0.3) contains a Server-Side Request Forgery flaw where an attacker-controlled URL in the request path can override the configured proxy target, causing the backend to fetch and return arbitrary remote content.
6
The SAML Single Sign On – SSO Login WordPress plugin (through 5.4.3) is vulnerable to authentication bypass via Signature Algorithm Confusion, as it reads the signing algorithm from attacker-controlled SAML response data rather than enforcing a locally configured value.
7
CVE-2026-12492CVSS 9.8PoCaffects Happy Coders OTP Login for WooCommerce The Happy Coders OTP Login for WooCommerce plugin (before 2.8) skips actual OTP validation before authenticating users, allowing unauthenticated attackers to log in as any user including administrators — a proof-of-concept is already available, raising the urgency.
8
Bricksforge for WordPress (through 3.1.8.6) allows unauthenticated attackers to escalate to administrator by abusing improper validation of field IDs in the Pro Forms registration flow, enabling full site takeover without credentials.
9
A third critical flaw in Jupyter Enterprise Gateway allows bypassing the prohibited UID/GID 0 restriction through a specially crafted KERNEL_UID or KERNEL_GID value, potentially launching Kubernetes kernels as root and undermining cluster isolation.
10
Improper input validation in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows may allow an unauthenticated network attacker to perform account takeover — a high-impact flaw given Zoom's ubiquity in enterprise environments.
Ransomware today
Ransomware activity against Brazilian organizations has been intense in recent days, with LockBit5 claiming the largest share of victims including educational institutions sesi.org.br, senai.br, and cmc.com.br, alongside business services firms aditusbr.com, montaury.com.br, and consumer-facing drogales.com.br and sweetome.com. RansomHouse added Megawork to its list, while the group Settra claimed acilab.com in the technology sector. Over the past 30 days, LockBit3, LockBit5, and RansomHub have each exceeded 35 confirmed victims in Brazil alone, reflecting a sustained and focused campaign against the country.
cmc.com.br BRlockbit5 · Education
acilab.com BRsettra · Technology
Megawork BRransomhouse · Business Services
sesi.org.br BRlockbit5 · Education
senai.br BRlockbit5 · Education
aditusbr.com BRlockbit5 · Business Services
drogales.com.br BRlockbit5 · Consumer Services
montaury.com.br BRlockbit5 · Business Services
sweetome.com BRlockbit5 · Consumer Services
lockbit3 39lockbit5 36ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated, including Iranian-linked actors BlackShadow and CopyKittens, along with APT73, DragonForce, AgainstTheWest, and CoinbaseCartel. While no confirmed new victims are attributed to these groups in the current reporting window, their continued operational tracking signals maintained capability and potential for near-term activity.
Brazil focus
Brazil remains one of the most heavily targeted countries in the current ransomware landscape, with LockBit5 alone claiming multiple victims across education and business services sectors in recent days. The breadth of targets — ranging from professional training bodies like SENAI and SESI to small businesses and consumer services — indicates opportunistic as well as strategic targeting. Security teams in Brazilian organizations should treat ransomware exposure as an active and immediate threat, not a theoretical risk.
montaury.com.brlockbit5 · Business Services
drogales.com.brlockbit5 · Consumer Services
senai.brlockbit5 · Education
Megaworkransomhouse · Business Services
sesi.org.brlockbit5 · Education
aditusbr.comlockbit5 · Business Services
acilab.comsettra · Technology
cmc.com.brlockbit5 · Education
Today’s recommendation: Organizations running Jupyter Enterprise Gateway should upgrade to 3.3.0 immediately to address three separate CVSS 10.0 flaws; WordPress administrators should audit and patch the SAML SSO, OTP Login, and Bricksforge plugins without delay, prioritizing sites where unauthenticated registration or login is enabled.
Given the breadth of critical flaws published today — spanning cluster orchestration platforms, SSO systems, and widely deployed CMS plugins — now is the right moment to validate your own attack surface and confirm whether any of these components are reachable from untrusted networks.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →