Daily briefing · July 17, 2026

WordPress REST API Flaw Weaponized Same-Day, Five Langflow RCEs Drop Simultaneously

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

July 17, 2026 warrants close attention: a critical WordPress chain vulnerability (CVE-2026-63030) combining REST API route confusion with SQL injection was spotted by VulnCheck before any official CISA confirmation and was already carrying a functional exploit on the day it was disclosed — a same-day weaponization that leaves virtually no patching window. Alongside it, five critical vulnerabilities in IBM Langflow OSS landed at once, ranging from unsafe pickle deserialization to hard-coded credentials, painting a broad attack surface for AI workflow platforms. With 25 critical CVEs published on the day and one confirmed active exploitation signal, defenders should treat this as a day requiring immediate triage.

Today’s brief
  • CVE-2026-63030 (WordPress): same-day weaponization, VulnCheck detected active exploitation before CISA — patch or mitigate immediately
  • Five Langflow OSS critical flaws (RCE, privilege escalation, path traversal, hard-coded creds) disclosed simultaneously — versions up to 1.10.x are exposed
  • Two WordPress AI plugins (Aimogen Pro, AI Copilot) allow unauthenticated privilege escalation and administrator session hijacking
  • LockBit5 claimed at least 11 Brazilian victims recently across education, logistics, manufacturing, and services sectors
25
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-63030◆ VulnCheckCVSS 9.8Functional exploitsame dayaffects WordPress
A REST API batch endpoint route confusion in WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 chains with a WP_Query SQL injection (CVE-2026-60137) to enable full Remote Code Execution; a functional exploit was available on day zero and VulnCheck observed exploitation before any official KEV listing, making this the single most urgent item of the day.
2
CVE-2026-54159CVSS 10affects ps_facetedsearch
The PrestaShop ps_facetedsearch module (versions 3.0.0 through 4.0.4) deserializes user-supplied slider filter values from the URL into an internal cache without validation, exposing any store running this module to arbitrary object injection and potential remote code execution via crafted requests.
3
CVE-2026-8476CVSS 9.9affects Langflow OSS
IBM Langflow OSS 1.0.0–1.10.0 uses Python's pickle.loads() to deserialize disk-cached objects with no integrity check or authentication, meaning any attacker who can write to the cache directory can achieve arbitrary code execution under the Langflow service account.
4
CVE-2026-8481CVSS 9.9affects Langflow OSS
The POST /api/v1/validate/code endpoint in IBM Langflow OSS passes user-supplied Python code directly to exec() without sandboxing, granting any authenticated user the ability to run arbitrary system commands — a trivially exploitable design flaw in AI development environments.
5
CVE-2026-8635CVSS 9.9affects Langflow OSS
Authenticated users of IBM Langflow OSS 1.0.0–1.10.0 can escalate to superuser by directly manipulating the database, enabling full system compromise; combined with the other Langflow flaws disclosed today, the privilege chain from low-privilege user to root becomes straightforward.
6
CVE-2026-8859CVSS 9.9affects Langflow OSS
A path traversal vulnerability in IBM Langflow OSS's APIRequest component allows an attacker to write arbitrary files to unintended filesystem locations when the 'Save to File' feature is active, as Content-Disposition filenames from HTTP responses are not sanitized before path construction.
7
CVE-2026-9135CVSS 9.9affects Langflow OSS
IBM Langflow OSS versions up to 1.9.2 contain a code injection flaw in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false control by only validating the main component source, leaving secondary code paths fully executable — a security bypass that undermines a key hardening setting.
8
CVE-2026-15982CVSS 9.8affects Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit
The Aimogen Pro WordPress plugin through version 2.8.4 lacks a capability check on the 'aiomatic_call_google_ai_function' function, allowing completely unauthenticated attackers to invoke the 'aimogen_wp_god_mode' tool and clear function access controls, effectively granting full site takeover without credentials.
9
CVE-2026-9810CVSS 9.8PoCaffects AI Copilot
The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a specific WordPress user, so any attacker who completes the public OAuth flow can present a valid token and be treated as an administrator, enabling arbitrary user creation and role escalation without any prior authentication.
10
CVE-2026-13446CVSS 9.8affects Langflow OSS
IBM Langflow OSS 1.0.0–1.10.1 ships with hard-coded credentials used for inbound authentication and internal data encryption; any attacker with access to the source code or binary can extract these credentials and authenticate to or decrypt data from any deployed instance.
Ransomware today

LockBit5 has been particularly aggressive against Brazilian targets recently, claiming at least 11 victims including SENAI and FIEPE (Education), Erstransportes (Transportation/Logistics), Brassuco (Agriculture), and Fast Indústria (Manufacturing), among others in Business and Consumer Services. Over the past 30 days, LockBit5 leads Brazilian victim counts with 42 claimed organizations, followed by LockBit3 (39), RansomHub (35), TheGentlemen (20), 8Base (20), and ArcusMedia (19) — indicating Brazil remains a high-intensity target environment across all major ransomware operators. The group Settra also claimed acilab.com in the Technology sector, broadening the threat actor landscape beyond the LockBit family.

audiconcontadores.com.br BRlockbit5 · Business Services
erstransportes.com.br BRlockbit5 · Transportation/Logistics
5deagosto.com.br BRlockbit5 · Consumer Services
fiepe.org.br BRlockbit5 · Education
brassuco.com.br BRlockbit5 · Agriculture and Food Production
fastindustria.com.br BRlockbit5 · Manufacturing
senai.br BRlockbit5 · Education
aditusbr.com BRlockbit5 · Business Services
drogales.com.br BRlockbit5 · Consumer Services
montaury.com.br BRlockbit5 · Business Services
cmc.com.br BRlockbit5 · Education
acilab.com BRsettra · Technology
lockbit5 42lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors are currently flagged as active or updated in threat intelligence feeds: APT73, the Iranian-linked groups BlackShadow and CopyKittens, as well as CoinbaseCartel, DragonForce, and AgainstTheWest. While no specific new victims have been attributed to these groups in the current period, their active status in intelligence platforms signals ongoing reconnaissance or operational readiness that defenders — particularly in sectors historically targeted by Iranian APTs — should factor into their monitoring posture.

Brazil focus

Brazil is facing an exceptionally concentrated ransomware campaign, with LockBit5 alone claiming over a dozen Brazilian victims recently spanning critical sectors such as education (SENAI, FIEPE, CMC), logistics, manufacturing, agriculture, and business services. Additionally, RansomHouse claimed Megawork in the Business Services sector, reinforcing that Brazilian organizations across all sizes and verticals are actively being targeted. The volume and sector diversity of these incidents underscores the need for Brazilian defenders to treat ransomware readiness — including tested backups and incident response plans — as an immediate operational priority.

fastindustria.com.brlockbit5 · Manufacturing
fiepe.org.brlockbit5 · Education
erstransportes.com.brlockbit5 · Transportation/Logistics
brassuco.com.brlockbit5 · Agriculture and Food Production
5deagosto.com.brlockbit5 · Consumer Services
audiconcontadores.com.brlockbit5 · Business Services
Megaworkransomhouse · Business Services
aditusbr.comlockbit5 · Business Services
Today’s recommendation: Administrators running WordPress 6.9.x or 7.0.x should update to 6.9.5 or 7.0.2 immediately given same-day weaponization of CVE-2026-63030; Langflow OSS deployments should be isolated from untrusted networks and updated to a patched release, with particular attention to disabling the code validation endpoint until all five critical CVEs are addressed.
Given the breadth of critical vulnerabilities across web platforms, AI development tools, and WordPress plugins disclosed today, now is the right moment to validate which of these products are actually running in your environment and confirm whether your exposure has already been tested against an attacker's perspective.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →