Daily briefing · July 24, 2026
Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 24, 2026 recorded 181 new CVEs with 10 critical-severity entries and zero confirmed active exploitations, placing the day firmly in the calm range. Despite the absence of weaponized exploits, three perfect-score CVSS 10.0 vulnerabilities in Microsoft Azure services demand immediate attention from cloud defenders. No KEV additions and no VulnCheck early-warning signals were recorded, but the severity and breadth of the Microsoft cloud disclosures keep this from being a routine day.
Today’s brief
- Three CVSS 10.0 flaws hit Azure Kubernetes Service, Azure App Service for Linux, and Microsoft Purview — all enabling privilege escalation over the network with no authentication required.
- Zero active exploitations confirmed, but high-severity cloud and industrial control system bugs raise the defensive bar for this cycle.
- A WordPress plugin SQL injection (CVE-2026-12877) with a public proof of concept threatens unauthenticated attackers on sites running unpatched versions.
- Brazil continues to be a ransomware hotspot, with multiple sectors hit recently by groups including qilin, lockbit5, nova, and Doommageddon.
Critical highlights
1
A missing authentication flaw in Azure Kubernetes Service allows any unauthenticated network attacker to escalate privileges to full cluster control — a CVSS 10.0 rating that warrants treating this as a drop-everything patch for any AKS deployment.
2
Improper access control in Azure App Service for Linux carries a perfect 10.0 score and enables remote privilege escalation without credentials, exposing every hosted workload on an unpatched instance to full compromise.
3
An SSRF vulnerability in Microsoft Purview Data Governance's Data Quality component scores CVSS 10.0 and lets an unauthenticated attacker escalate privileges, potentially pivoting to internal Azure infrastructure from a public endpoint.
4
Eclipse BaSyx Go Components up to v1.0.0 contain an authorization bypass caused by inconsistent trailing-slash handling, allowing attackers to circumvent ABAC controls entirely — critical for any IIoT or Industry 4.0 deployment relying on BaSyx access policies.
5
SUNNET Corporate Training Management System allows authenticated administrators to upload a crafted ZIP archive containing a server-executable file, achieving remote command execution — the administrator-privilege requirement lowers immediate risk but makes lateral-movement scenarios realistic.
6
Tycon Systems TPDIN-Monitor-WEB2 skips server-side credential validation entirely, meaning an unauthenticated attacker can submit empty credentials and gain full administrative access — including control of physical power relays, a significant operational technology risk.
7
Improper authorization in Azure Portal permits an unauthenticated network attacker to disclose sensitive information, adding another entry to this cycle's Azure surface-area concerns and reinforcing the need to audit portal access controls.
8
A symlink attack vulnerability in Loytec's L-DALI and related firmware allows an authenticated larmapp user to make /etc/passwd group-writable, providing a clear path to root privilege escalation — particularly dangerous in building automation and industrial environments where these devices are widely deployed.
9
CVE-2026-12877CVSS 9.1PoCaffects Project Management, Bug and Issue Tracking Plugin An unauthenticated SQL injection in the Project Management, Bug and Issue Tracking WordPress plugin before 5.1.0 already has a public proof of concept, making exploitation by opportunistic attackers against unpatched sites a realistic near-term threat.
10
In epa4all prior to the 2026-05-20 release, an attacker capable of intercepting the TLS channel can hijack the VAU handshake and decrypt all inner HTTP traffic — including patient consent decisions and medication data — representing a serious healthcare data-integrity and privacy risk.
Ransomware today
The qilin group has claimed Cpcg, a Brazilian organization in the Other sector, as a recent victim. Among the most active groups over the past 30 days, lockbit5 leads with 49 recorded attacks, followed by lockbit3 (39), ransomhub (35), thegentlemen and 8base (20 each), and arcusmedia (19), underscoring a sustained and broad ransomware campaign landscape.
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors have been flagged as active or updated in this cycle: blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73 are all currently tracked, though no confirmed victims have been attributed to these specific groups in the current period. Their presence in threat intelligence feeds warrants monitoring, particularly for organizations in sectors historically targeted by Iranian state-aligned actors.
Brazil focus
Brazil remains under sustained ransomware pressure, with recent victims spanning multiple sectors: Cpcg and PP+K were claimed by qilin, guarnera.com.br and gruposelpe.com.br by lockbit5, Reni Farmácias Associadas (healthcare) by Doommageddon, CCR Solutions by unsafe, and FMZ Tecnologia em Sistemas and Jota Joias Premium by a group tracked as nova. The breadth of targeted sectors — retail, healthcare, manufacturing, technology, and professional services — reflects a deliberate and wide-scope offensive against Brazilian organizations.
Cpcgqilin · Other
Jota Joias Premiumnova · Retail & E-Commerce
CCR Solutionsunsafe · Business Services
Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin · Manufacturing
FMZ Tecnologia em Sistemasnova · Technology
guarnera.com.brlockbit5 · Professional Services
gruposelpe.com.brlockbit5 · Professional Services
Today’s recommendation: Organizations running Azure Kubernetes Service, Azure App Service for Linux, or Microsoft Purview should treat today's three CVSS 10.0 disclosures as priority patches and verify network access controls are limiting exposure while fixes are applied. Simultaneously, WordPress administrators should update the Project Management, Bug and Issue Tracking Plugin to 5.1.0 or later given the publicly available proof of concept for unauthenticated SQL injection.
Even on a day with no confirmed active exploitations, the presence of perfect-score cloud flaws and a public SQL injection PoC is a reminder that validating your own attack surface — before adversaries do — is what separates a managed risk posture from an unpleasant surprise.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →