Daily briefing · July 25, 2026
CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New Exploits
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 25, 2026 closes without any active exploitation or weaponized vulnerabilities, placing the day firmly in the calm category — but the vulnerability list still demands attention. Two critical-severity flaws top the rankings, including a perfect CVSS 10.0 in the SiYuan note-taking platform and an authentication bypass in OpenRemote, both published today and carrying significant exposure potential for unpatched deployments.
Today’s brief
- No active exploitation or KEV entries recorded today — monitor rather than emergency-patch
- CVE-2026-66012 scores CVSS 10.0 in SiYuan: full workspace file access via unauthenticated MCP endpoint when Publish server runs in anonymous mode
- CVE-2026-66013 hits CVSS 9.3 in OpenRemote: unauthenticated attackers can hijack push notification tokens by supplying a known asset ID
- WordPress ecosystem again heavily represented: Fluent Forms Pro, WPForms Pro, Checkout Field Editor, and Yoast SEO all carry exploitable flaws today
Critical highlights
1
A missing authorization flaw in SiYuan's POST /mcp kernel endpoint exposes 31 MCP tools — including full file read, write, delete, rename, and copy — across the entire workspace when the Publish server runs in anonymous mode. With a perfect CVSS 10.0 and no authentication required in that configuration, any network-reachable attacker gains de facto full workspace control; operators should upgrade to v3.7.2 immediately and audit Publish server settings.
2
OpenRemote before 1.26.2 allows unauthenticated attackers to overwrite push notification tokens and console metadata on any asset whose identifier is known, effectively redirecting or blocking legitimate notifications. The absence of any ownership validation in the console registration API makes this trivially exploitable against exposed OpenRemote instances.
3
The Fluent Forms Pro Add On Pack for WordPress (up to 6.2.6) is vulnerable to PHP Object Injection via deserialization, reachable by any subscriber-level authenticated user. A POP chain already present in the environment allows full account takeover through password changes — a low bar for privilege escalation on multi-user WordPress sites.
4
WPForms Pro (up to 1.10.1.1) permits unauthenticated arbitrary file upload because file-type validation happens after chunk assembly, and validation failures do not delete the assembled file from disk. This leaves a window for remote code execution on any affected WordPress installation without requiring any login.
5
CVE-2026-14955MEDIUM 6.5affects Checkout Field Editor for WooCommerce (Pro) Checkout Field Editor for WooCommerce (Pro) up to 3.7.7 allows subscriber-level users to exploit a directory traversal via the 'thwcfe_legacy_file' parameter, exposing arbitrary server-side files including credentials and configuration data. Sensitive data disclosure at low privilege is a common precursor to deeper compromise.
6
Zephyr's userspace dynamic-objects subsystem contains a race condition in thread_idx_alloc() on SMP systems: two concurrent k_object_alloc(K_OBJ_THREAD) syscalls can obtain the same thread permission index, leading to privilege confusion or memory corruption in embedded and IoT environments.
7
CVE-2026-15425MEDIUM 6.4affects Yoast SEO – Advanced SEO with real-time guidance and built-in AI Yoast SEO up to version 28.0 allows author-level authenticated users to store arbitrary JavaScript via the post slug field, which executes when affected pages are visited by administrators or other users. Stored XSS at author level is particularly dangerous in editorial workflows with shared access.
8
NanoClaw up to 2.0.64 has an improper authorization flaw in the MCP Server Approval component, exploitable locally, with a public proof-of-concept already available. While the local attack vector limits immediate blast radius, the public PoC accelerates the window for exploitation by insiders or post-compromise attackers.
9
ImageMagick before 7.1.2-27 leaks memory when malformed command-line arguments are supplied, allowing repeated invocations to exhaust system resources. In environments where ImageMagick processes user-supplied input — such as web applications handling image uploads — this is a practical denial-of-service vector.
10
A remote improper access control flaw in the SimpleX Gateway Authorization component of hermes-agent (NousResearch, version 2026.6.5) has a public proof of concept, though high attack complexity reduces immediate risk. Organizations running this AI agent platform should monitor for exploitation activity given the public PoC availability.
Ransomware today
Ransomware activity targeting Brazil remains significant in recent days, with msgas.com.br (Energy & Utilities) claimed by blackwater and Cpcg (Other sector) claimed by qilin. Over the past 30 days, lockbit5 has been the most active group with 49 recorded attacks, followed by lockbit3 (39), ransomhub (35), thegentlemen (20), 8base (20), and arcusmedia (19) — all with a notable focus on Brazilian victims.
msgas.com.br BRblackwater · Energy & Utilities
Cpcg BRqilin · Other
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors are currently being tracked with updated activity profiles, including the Iranian-linked group blackshadow, as well as coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. While no confirmed victims are attributed to these groups at this time, their active monitoring status indicates ongoing operational posture that warrants defensive attention, particularly for organizations in sectors historically targeted by Iranian-nexus actors.
Brazil focus
Brazil's threat landscape remains under sustained pressure, with eight organizations across diverse sectors recorded as ransomware victims in recent weeks: msgas.com.br (Energy), Cpcg (Other), Jota Joias Premium (Retail), Reni Farmácias Associadas (Healthcare), CCR Solutions (Business Services), PP+K (Manufacturing), gruposelpe.com.br (Professional Services), and kenta.com.br (Technology). The breadth of targeted sectors — from critical infrastructure to retail — underscores that no vertical is currently out of scope for Brazilian-focused ransomware operators.
msgas.com.brblackwater · Energy & Utilities
Cpcgqilin · Other
Jota Joias Premiumnova · Retail & E-Commerce
Reni Farmácias AssociadasDoommageddon · Healthcare
CCR Solutionsunsafe · Business Services
PP+Kqilin · Manufacturing
gruposelpe.com.brlockbit5 · Professional Services
kenta.com.brlockbit5 · Technology
Today’s recommendation: Prioritize patching CVE-2026-66012 in SiYuan and CVE-2026-66013 in OpenRemote given their critical CVSS scores and unauthenticated attack paths; simultaneously audit WordPress plugin versions across your estate, as four high-to-medium severity flaws published today collectively cover widely deployed plugins. Confirm that file upload endpoints, deserialization paths, and anonymous-access server configurations are explicitly reviewed in your next change window.
With unauthenticated attack paths appearing even on calm vulnerability days, validating your actual external and internal exposure — rather than assuming low activity means low risk — is the only reliable way to know whether today's findings affect your environment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →