Daily briefing · July 23, 2026
VulnCheck Flags Fastjson RCE in the Wild as Wave of CVSS 10 Flaws Hits Azure, Exchange, and Dev Tools
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
July 23, 2026 warrants attention: while no KEV entries were formally added by CISA, VulnCheck independently observed active exploitation of a critical Fastjson RCE vulnerability before any official confirmation — a signal defenders cannot ignore. The day also brought a dense cluster of CVSS 10.0 disclosures spanning Azure DNS, Azure Key Vault, Microsoft Exchange Online, ManageEngine ADAudit Plus, JetBrains IntelliJ IDEA, and open-source tools, totaling 54 critical CVEs among 384 new entries. The combination of an in-the-wild exploit and multiple maximum-severity flaws makes this a patch-and-verify day for security teams.
Today’s brief
- VulnCheck observed active exploitation of CVE-2026-16723 (Fastjson RCE) before CISA — no AutoType or special config required, raising the urgency bar immediately.
- Seven CVSS 10.0 vulnerabilities were disclosed today alone, covering Azure DNS, Azure Key Vault, Exchange Online, DbGate, ManageEngine ADAudit Plus, IntelliJ IDEA, and cal.diy.
- CVE-2026-47668 (DbGate) carries a functional exploit, meaning attack capability is already packaged and accessible to threat actors.
- Brazil is heavily targeted: eight Brazilian organizations appear as ransomware victims recently, with lockbit5, qilin, and Doommageddon among active groups.
Critical highlights
1
A remote code execution flaw in Fastjson 1.2.68–1.2.83 that requires no AutoType enablement and no classpath gadget — meaning the vast majority of Fastjson deployments in their default state are exposed. VulnCheck flagged this as actively exploited before CISA, making it the top priority of the day regardless of its modest 1% EPSS score.
2
A missing authorization flaw in Azure DNS rated CVSS 10.0 enables an unauthenticated network attacker to elevate privileges — a critical risk for any organization relying on Azure-hosted DNS infrastructure without compensating network controls.
3
Improper authentication in Azure Key Vault allows privilege escalation over the network without credentials, threatening the integrity of secrets, certificates, and cryptographic keys stored in one of Azure's most sensitive services.
4
A CVSS 10.0 improper authentication bug in Microsoft Exchange Online enables unauthenticated network attackers to tamper with email infrastructure, which could facilitate message interception, spoofing, or business email compromise at scale.
5
An unintended proxy vulnerability in Panduit IntraVUE (versions 3.2.1a14 and prior) allows attackers to route traffic through an active proxy, effectively bypassing OT network segmentation — a severe risk in industrial and critical infrastructure environments.
6
Cal.com's self-hosted variant (cal.diy) before 5.9.9 is vulnerable to unauthenticated RCE through a flawed Next.js React Server Components implementation that deserializes attacker-controlled input — no authentication or user interaction required, making this trivially weaponizable against exposed scheduling servers.
7
DbGate versions 7.1.8 and prior allow remote code execution via code injection in the JSON script runner endpoint, and a functional exploit already exists — defenders running DbGate in any network-accessible configuration should treat this as an immediate patching emergency.
8
ManageEngine ADAudit Plus before version 8606 exposes an unauthenticated RCE path through a vulnerable agent API, targeting a tool widely deployed for Active Directory monitoring — compromise here could give attackers deep visibility into and control over identity infrastructure.
9
In JetBrains IntelliJ IDEA before 2026.2, a Remote Development session can be abused by an unauthorized party to modify IDE settings, which may enable persistence or facilitate supply chain attacks against developers and their code repositories.
10
Also in IntelliJ IDEA before 2026.2, unauthorized input injection is possible during Remote Development sessions — when combined with CVE-2026-64813, attackers targeting developer workstations have two complementary vectors to abuse in the same product.
Ransomware today
The qilin group was recently linked to a new Brazilian victim, Cpcg (Other sector), adding to a pattern of Brazilian organizations being hit across multiple ransomware crews. Over the past 30 days, the most active groups have been lockbit5 (49 incidents), lockbit3 (39), ransomhub (35), thegentlemen (20), 8base (20), and arcusmedia (19) — all of which show a notable concentration of Brazilian victims in their respective portfolios.
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors and APT groups are currently being tracked as active or recently updated, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. While no confirmed victims are attributed to these groups in the current window, their active tracking status indicates ongoing operational reconnaissance or campaign preparation that defenders should monitor.
Brazil focus
Brazil is under sustained ransomware pressure: in recent weeks, eight Brazilian organizations across diverse sectors have been listed as victims, including Reni Farmácias Associadas (Healthcare, Doommageddon), PP+K (Manufacturing, qilin), CCR Solutions (Business Services, unsafe), Jota Joias Premium (Retail & E-Commerce, nova), and three organizations hit by lockbit5 — gruposelpe.com.br, grupoferrosider.com.br, and guarnera.com.br. The breadth of sectors targeted — healthcare, manufacturing, retail, professional services — underscores that no vertical is being spared in the current threat environment.
Cpcgqilin · Other
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin · Manufacturing
CCR Solutionsunsafe · Business Services
Jota Joias Premiumnova · Retail & E-Commerce
gruposelpe.com.brlockbit5 · Professional Services
grupoferrosider.com.brlockbit5 · Manufacturing
guarnera.com.brlockbit5 · Professional Services
Today’s recommendation: Security teams should immediately assess all Fastjson deployments for CVE-2026-16723 and apply vendor patches, given confirmed in-the-wild exploitation; simultaneously, Azure administrators should review authorization controls for DNS and Key Vault while dev teams validate IntelliJ IDEA and DbGate versions. Prioritize ManageEngine ADAudit Plus upgrades to version 8606 or later, as unauthenticated RCE in an Active Directory auditing tool represents a direct path to identity infrastructure compromise.
With active exploitation already observed before official confirmation and a functional exploit circulating for DbGate, now is the moment to validate whether your own attack surface is exposed to these vectors — not after an incident.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →