Daily briefing · July 26, 2026

Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple Groups

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 26, 2026 registers as a calm day on the vulnerability front, with 15 new CVEs published, one rated Critical, and zero confirmed active exploits or weaponized proof-of-concepts. The Linux kernel leads the highlights with a CVSS 9.8 flaw, followed by a cluster of high-severity issues in NoteGen, Microsoft Edge, and AI tooling. While defenders can take a measured approach to patching today, the ransomware landscape targeting Brazilian organizations demands immediate attention.

Today’s brief
  • Linux kernel CVE-2026-64530 scores CVSS 9.8 but has no known exploits yet — patch promptly as kernel flaws attract rapid weaponization
  • NoteGen users below 0.32.0 face two chained high-severity risks: arbitrary OS command execution and unsanitized AI-driven HTML injection
  • Three Microsoft Edge vulnerabilities disclosed today expose users to information disclosure and spoofing via origin validation errors
  • Brazil is under active ransomware pressure: Section9, Global Secret Group, arcusmedia, and blackwater have hit multiple sectors in recent days
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-64530CVSS 9.8affects Linux
A critical use-after-free class flaw in the Linux kernel's traffic control subsystem (cls_api) where tcf_qevent_handle fails to respect the TC_ACT_CONSUMED return, allowing access to an skb no longer owned by the caller — network-reachable scenarios make this CVSS 9.8 rating credible and warrant priority patching across all Linux deployments.
2
CVE-2026-17497HIGH 8.3affects NoteGen
NoteGen before 0.32.0 exposes the Tauri shell plugin with broad execution permissions for bash, python, and python3, meaning any JavaScript running in the webview can invoke arbitrary OS commands at the process's privilege level — a critical attack surface for desktop AI note-taking users.
3
CVE-2026-15928HIGH 8.2affects XMLRPC-C
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to reflected XSS in the error page component, which could allow attackers to inject and execute malicious scripts in victim browsers interacting with affected XML-RPC endpoints.
4
CVE-2026-17496HIGH 8.1affects NoteGen
NoteGen before 0.32.0 renders AI chat responses as raw HTML with no sanitization and a null CSP, meaning attacker-controlled content injected into the model prompt — such as a malicious skill REFERENCE.md — can result in stored or reflected XSS within the application context.
5
CVE-2026-63720HIGH 7.5affects datamodel-code-generator
datamodel-code-generator before 0.70.0 contains a code injection flaw where a malicious customBasePath value with embedded newlines is written verbatim into generated Python import statements, enabling remote code execution for any workflow that processes attacker-controlled schemas.
6
CVE-2026-57990HIGH 7.4affects Microsoft Edge (Chromium-based)
A file and directory exposure vulnerability in Microsoft Edge (Chromium-based) allows network-adjacent unauthorized attackers to access and disclose sensitive information — organizations relying on Edge for internal or sensitive workflows should prioritize the available update.
7
CVE-2026-57989HIGH 7.4affects Microsoft Edge (Chromium-based)
An origin validation error in Microsoft Edge (Chromium-based) enables unauthorized network attackers to perform information disclosure, potentially leaking cross-origin data from browsing sessions — apply the latest Edge update immediately.
8
CVE-2026-17501MEDIUM 6.9affects llama.cpp
A resource allocation flaw in llama.cpp's JSON-Schema-to-GBNF conversion function (json-schema-to-grammar.cpp) can be triggered remotely, with a pending fix not yet merged — organizations running llama.cpp inference services exposed to external input should monitor the upstream pull request closely.
9
CVE-2026-17500MEDIUM 6.9affects llama.cpp
A null pointer dereference in llama.cpp's _visit_pattern function can be triggered remotely via crafted JSON schema input; the fix is awaiting acceptance upstream, leaving deployed instances temporarily exposed to potential denial-of-service or worse.
10
CVE-2026-57978MEDIUM 5.4affects Microsoft Edge (Chromium-based)
A second origin validation error in Microsoft Edge (Chromium-based) enables network-based spoofing attacks, which could be used to deceive users about the origin of content they are viewing — part of a trio of Edge flaws disclosed today that collectively raise the browser's attack surface.
Ransomware today

Brazil is experiencing concentrated ransomware activity across multiple sectors. Section9 has claimed several Brazilian victims recently spanning Financial Services, Technology, Agriculture, and other sectors, while Global Secret Group has targeted Sinop Energia (Energy & Utilities) and SPDM (Healthcare). Additionally, arcusmedia hit Power Moendas and blackwater claimed msgas.com.br in the Energy & Utilities sector, underscoring that no industry vertical in Brazil is out of scope. Among the most active groups over the past 30 days, lockbit5 and lockbit3 each account for nearly 40 or more attacks, with ransomhub, thegentlemen, 8base, and arcusmedia also highly active.

********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 20
Active groups & APTs

Several threat actor groups have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. None of these groups currently have confirmed attributed victims in this reporting window, but their presence in threat intelligence feeds suggests ongoing reconnaissance or preparation activity that defenders should monitor.

Brazil focus

Brazil remains one of the most targeted countries in this reporting period, with ransomware groups hitting organizations across Energy & Utilities, Healthcare, Financial Services, Technology, and Agriculture. Notable named victims include Sinop Energia (Global Secret Group), SPDM (Global Secret Group), and Power Moendas (arcusmedia), alongside multiple redacted Brazilian domains claimed by Section9. The breadth of sectors affected signals that Brazilian organizations of all sizes and industries should treat ransomware preparedness as an operational priority.

******.com.brSection9 · Other
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
******.net.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Prioritize patching CVE-2026-64530 in all Linux kernel deployments and update NoteGen to 0.32.0 or later to address the command execution and HTML injection chain; also apply the latest Microsoft Edge update to close the trio of information disclosure and spoofing flaws disclosed today.
Regardless of whether today's vulnerabilities appear in your asset inventory, validating your actual attack surface — including exposed services, AI tooling integrations, and browser policies — is the only reliable way to know if your organization is truly insulated from these risks.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →