Daily briefing · July 25, 2026
CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New Exploits
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 25, 2026 closes without any active exploitation or weaponized vulnerabilities, placing the day firmly in the calm category — but the vulnerability list still demands attention. Two critical-severity flaws top the rankings, including a perfect CVSS 10.0 in the SiYuan note-taking platform and an authentication bypass in OpenRemote, both published today and carrying significant exposure potential for unpatched deployments.
Today’s brief
- No active exploitation or KEV entries recorded today — monitor rather than emergency-patch
- CVE-2026-66012 scores CVSS 10.0 in SiYuan: full workspace file access via unauthenticated MCP endpoint when Publish server runs in anonymous mode
- CVE-2026-66013 hits CVSS 9.3 in OpenRemote: unauthenticated attackers can hijack push notification tokens by supplying a known asset ID
- WordPress ecosystem again heavily represented: Fluent Forms Pro, WPForms Pro, Checkout Field Editor, and Yoast SEO all carry exploitable flaws today
Critical highlights
1
A missing authorization flaw in SiYuan's POST /mcp kernel endpoint exposes 31 MCP tools — including full file read, write, delete, rename, and copy — across the entire workspace when the Publish server runs in anonymous mode. With a perfect CVSS 10.0 and no authentication required in that configuration, any network-reachable attacker gains de facto full workspace control; operators should upgrade to v3.7.2 immediately and audit Publish server settings.
2
OpenRemote before 1.26.2 allows unauthenticated attackers to overwrite push notification tokens and console metadata on any asset whose identifier is known, effectively redirecting or blocking legitimate notifications. The absence of any ownership validation in the console registration API makes this trivially exploitable against exposed OpenRemote instances.
3
The Fluent Forms Pro Add On Pack for WordPress (up to 6.2.6) is vulnerable to PHP Object Injection via deserialization, reachable by any subscriber-level authenticated user. A POP chain already present in the environment allows full account takeover through password changes — a low bar for privilege escalation on multi-user WordPress sites.
4
WPForms Pro (up to 1.10.1.1) permits unauthenticated arbitrary file upload because file-type validation happens after chunk assembly, and validation failures do not delete the assembled file from disk. This leaves a window for remote code execution on any affected WordPress installation without requiring any login.
5
CVE-2026-14955MEDIUM 6.5affects Checkout Field Editor for WooCommerce (Pro) Checkout Field Editor for WooCommerce (Pro) up to 3.7.7 allows subscriber-level users to exploit a directory traversal via the 'thwcfe_legacy_file' parameter, exposing arbitrary server-side files including credentials and configuration data. Sensitive data disclosure at low privilege is a common precursor to deeper compromise.
6
Zephyr's userspace dynamic-objects subsystem contains a race condition in thread_idx_alloc() on SMP systems: two concurrent k_object_alloc(K_OBJ_THREAD) syscalls can obtain the same thread permission index, leading to privilege confusion or memory corruption in embedded and IoT environments.
7
CVE-2026-15425MEDIUM 6.4affects Yoast SEO – Advanced SEO with real-time guidance and built-in AI Yoast SEO up to version 28.0 allows author-level authenticated users to store arbitrary JavaScript via the post slug field, which executes when affected pages are visited by administrators or other users. Stored XSS at author level is particularly dangerous in editorial workflows with shared access.
8
NanoClaw up to 2.0.64 has an improper authorization flaw in the MCP Server Approval component, exploitable locally, with a public proof-of-concept already available. While the local attack vector limits immediate blast radius, the public PoC accelerates the window for exploitation by insiders or post-compromise attackers.
9
ImageMagick before 7.1.2-27 leaks memory when malformed command-line arguments are supplied, allowing repeated invocations to exhaust system resources. In environments where ImageMagick processes user-supplied input — such as web applications handling image uploads — this is a practical denial-of-service vector.
10
A remote improper access control flaw in the SimpleX Gateway Authorization component of hermes-agent (NousResearch, version 2026.6.5) has a public proof of concept, though high attack complexity reduces immediate risk. Organizations running this AI agent platform should monitor for exploitation activity given the public PoC availability.
Ransomware today
Ransomware activity targeting Brazil remains significant in recent days, with msgas.com.br (Energy & Utilities) claimed by blackwater and Cpcg (Other sector) claimed by qilin. Over the past 30 days, lockbit5 has been the most active group with 49 recorded attacks, followed by lockbit3 (39), ransomhub (35), thegentlemen (20), 8base (20), and arcusmedia (19) — all with a notable focus on Brazilian victims.
msgas.com.br BRblackwater · Energy & Utilities
Cpcg BRqilin · Other
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors are currently being tracked with updated activity profiles, including the Iranian-linked group blackshadow, as well as coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. While no confirmed victims are attributed to these groups at this time, their active monitoring status indicates ongoing operational posture that warrants defensive attention, particularly for organizations in sectors historically targeted by Iranian-nexus actors.
Brazil focus
Brazil's threat landscape remains under sustained pressure, with eight organizations across diverse sectors recorded as ransomware victims in recent weeks: msgas.com.br (Energy), Cpcg (Other), Jota Joias Premium (Retail), Reni Farmácias Associadas (Healthcare), CCR Solutions (Business Services), PP+K (Manufacturing), gruposelpe.com.br (Professional Services), and kenta.com.br (Technology). The breadth of targeted sectors — from critical infrastructure to retail — underscores that no vertical is currently out of scope for Brazilian-focused ransomware operators.
msgas.com.brblackwater · Energy & Utilities
Cpcgqilin · Other
Jota Joias Premiumnova · Retail & E-Commerce
Reni Farmácias AssociadasDoommageddon · Healthcare
CCR Solutionsunsafe · Business Services
PP+Kqilin · Manufacturing
gruposelpe.com.brlockbit5 · Professional Services
kenta.com.brlockbit5 · Technology
Today’s recommendation: Prioritize patching CVE-2026-66012 in SiYuan and CVE-2026-66013 in OpenRemote given their critical CVSS scores and unauthenticated attack paths; simultaneously audit WordPress plugin versions across your estate, as four high-to-medium severity flaws published today collectively cover widely deployed plugins. Confirm that file upload endpoints, deserialization paths, and anonymous-access server configurations are explicitly reviewed in your next change window.
With unauthenticated attack paths appearing even on calm vulnerability days, validating your actual external and internal exposure — rather than assuming low activity means low risk — is the only reliable way to know whether today's findings affect your environment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →