Daily briefing · July 23, 2026

VulnCheck Flags Fastjson RCE in the Wild as Wave of CVSS 10 Flaws Hits Azure, Exchange, and Dev Tools

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

July 23, 2026 warrants attention: while no KEV entries were formally added by CISA, VulnCheck independently observed active exploitation of a critical Fastjson RCE vulnerability before any official confirmation — a signal defenders cannot ignore. The day also brought a dense cluster of CVSS 10.0 disclosures spanning Azure DNS, Azure Key Vault, Microsoft Exchange Online, ManageEngine ADAudit Plus, JetBrains IntelliJ IDEA, and open-source tools, totaling 54 critical CVEs among 384 new entries. The combination of an in-the-wild exploit and multiple maximum-severity flaws makes this a patch-and-verify day for security teams.

Today’s brief
  • VulnCheck observed active exploitation of CVE-2026-16723 (Fastjson RCE) before CISA — no AutoType or special config required, raising the urgency bar immediately.
  • Seven CVSS 10.0 vulnerabilities were disclosed today alone, covering Azure DNS, Azure Key Vault, Exchange Online, DbGate, ManageEngine ADAudit Plus, IntelliJ IDEA, and cal.diy.
  • CVE-2026-47668 (DbGate) carries a functional exploit, meaning attack capability is already packaged and accessible to threat actors.
  • Brazil is heavily targeted: eight Brazilian organizations appear as ransomware victims recently, with lockbit5, qilin, and Doommageddon among active groups.
54
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-16723◆ VulnCheckCVSS 9affects Fastjson
A remote code execution flaw in Fastjson 1.2.68–1.2.83 that requires no AutoType enablement and no classpath gadget — meaning the vast majority of Fastjson deployments in their default state are exposed. VulnCheck flagged this as actively exploited before CISA, making it the top priority of the day regardless of its modest 1% EPSS score.
2
CVE-2026-58275CVSS 10affects Azure DNS
A missing authorization flaw in Azure DNS rated CVSS 10.0 enables an unauthenticated network attacker to elevate privileges — a critical risk for any organization relying on Azure-hosted DNS infrastructure without compensating network controls.
3
CVE-2026-62825CVSS 10affects Azure Key Vault
Improper authentication in Azure Key Vault allows privilege escalation over the network without credentials, threatening the integrity of secrets, certificates, and cryptographic keys stored in one of Azure's most sensitive services.
4
CVE-2026-56191CVSS 10affects Microsoft Exchange Online
A CVSS 10.0 improper authentication bug in Microsoft Exchange Online enables unauthenticated network attackers to tamper with email infrastructure, which could facilitate message interception, spoofing, or business email compromise at scale.
5
CVE-2026-42933CVSS 10affects Panduit Intravue
An unintended proxy vulnerability in Panduit IntraVUE (versions 3.2.1a14 and prior) allows attackers to route traffic through an active proxy, effectively bypassing OT network segmentation — a severe risk in industrial and critical infrastructure environments.
6
CVE-2025-71389CVSS 10affects cal.diy
Cal.com's self-hosted variant (cal.diy) before 5.9.9 is vulnerable to unauthenticated RCE through a flawed Next.js React Server Components implementation that deserializes attacker-controlled input — no authentication or user interaction required, making this trivially weaponizable against exposed scheduling servers.
7
CVE-2026-47668CVSS 10Functional exploitaffects dbgate
DbGate versions 7.1.8 and prior allow remote code execution via code injection in the JSON script runner endpoint, and a functional exploit already exists — defenders running DbGate in any network-accessible configuration should treat this as an immediate patching emergency.
8
CVE-2026-6516CVSS 10affects ManageEngine ADAudit Plus
ManageEngine ADAudit Plus before version 8606 exposes an unauthenticated RCE path through a vulnerable agent API, targeting a tool widely deployed for Active Directory monitoring — compromise here could give attackers deep visibility into and control over identity infrastructure.
9
CVE-2026-64813CVSS 10affects IntelliJ IDEA
In JetBrains IntelliJ IDEA before 2026.2, a Remote Development session can be abused by an unauthorized party to modify IDE settings, which may enable persistence or facilitate supply chain attacks against developers and their code repositories.
10
CVE-2026-64812CVSS 10affects IntelliJ IDEA
Also in IntelliJ IDEA before 2026.2, unauthorized input injection is possible during Remote Development sessions — when combined with CVE-2026-64813, attackers targeting developer workstations have two complementary vectors to abuse in the same product.
Ransomware today

The qilin group was recently linked to a new Brazilian victim, Cpcg (Other sector), adding to a pattern of Brazilian organizations being hit across multiple ransomware crews. Over the past 30 days, the most active groups have been lockbit5 (49 incidents), lockbit3 (39), ransomhub (35), thegentlemen (20), 8base (20), and arcusmedia (19) — all of which show a notable concentration of Brazilian victims in their respective portfolios.

Cpcg BRqilin · Other
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors and APT groups are currently being tracked as active or recently updated, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. While no confirmed victims are attributed to these groups in the current window, their active tracking status indicates ongoing operational reconnaissance or campaign preparation that defenders should monitor.

Brazil focus

Brazil is under sustained ransomware pressure: in recent weeks, eight Brazilian organizations across diverse sectors have been listed as victims, including Reni Farmácias Associadas (Healthcare, Doommageddon), PP+K (Manufacturing, qilin), CCR Solutions (Business Services, unsafe), Jota Joias Premium (Retail & E-Commerce, nova), and three organizations hit by lockbit5 — gruposelpe.com.br, grupoferrosider.com.br, and guarnera.com.br. The breadth of sectors targeted — healthcare, manufacturing, retail, professional services — underscores that no vertical is being spared in the current threat environment.

Cpcgqilin · Other
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin · Manufacturing
CCR Solutionsunsafe · Business Services
Jota Joias Premiumnova · Retail & E-Commerce
gruposelpe.com.brlockbit5 · Professional Services
grupoferrosider.com.brlockbit5 · Manufacturing
guarnera.com.brlockbit5 · Professional Services
Today’s recommendation: Security teams should immediately assess all Fastjson deployments for CVE-2026-16723 and apply vendor patches, given confirmed in-the-wild exploitation; simultaneously, Azure administrators should review authorization controls for DNS and Key Vault while dev teams validate IntelliJ IDEA and DbGate versions. Prioritize ManageEngine ADAudit Plus upgrades to version 8606 or later, as unauthenticated RCE in an Active Directory auditing tool represents a direct path to identity infrastructure compromise.
With active exploitation already observed before official confirmation and a functional exploit circulating for DbGate, now is the moment to validate whether your own attack surface is exposed to these vectors — not after an incident.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →