Daily briefing · July 28, 2026
Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the List
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 28, 2026 recorded no actively exploited vulnerabilities and no weaponized exploits, placing it firmly in the calm category — but the day brought 253 new CVEs, 20 of them critical, demanding careful attention from defenders. Deserialization flaws and authentication bypass vulnerabilities dominate the highlights, with IBM WebSphere, Apache Axis2, and a Joomla extension carrying the highest risk profiles. While no active exploitation has been confirmed, the technical severity of several entries is high enough to treat them as urgent patching priorities.
Today’s brief
- No active exploitation or KEV entries today, but 20 critical CVEs published — calm does not mean safe.
- IBM WebSphere Application Server carries two CVSS 9.8 flaws: broken access control in the admin console and pre-authentication unsafe deserialization allowing RCE.
- Apache Axis2/Java deserialization (CVSS 9.8) and Balbooa Forms for Joomla unauthenticated RCE (CVSS 10.0) are high-priority patch targets.
- Brazil faces a wave of ransomware activity: Section9, Global Secret Group, and other groups have recently struck targets across energy, healthcare, financial services, and agriculture sectors.
Critical highlights
1
CVE-2026-11756CVSS 10affects Station Launcher App in 3DEXPERIENCE platform A CVSS 10.0 deserialization flaw in the Station Launcher App of Dassault's 3DEXPERIENCE platform allows unauthenticated remote code execution across releases R2023x through R2026x — a maximum-severity risk for enterprises running this PLM environment that should be patched immediately.
2
The terraform-mcp-server before 1.1.0 allows cross-tenant credential reuse in stateless HTTP transport mode, meaning one user's Terraform token could be leveraged to execute tool calls as another user — a critical supply chain and infrastructure automation risk in shared environments.
3
Unauthenticated remote code execution in the Balbooa Forms Joomla extension (before 2.4.3) stems from insecure form processing when a signature field type is present — any internet-facing Joomla site running this plugin should be considered fully compromised until patched.
4
CVE-2026-15014CVSS 9.8affects SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery The SMS Alert WordPress plugin (up to 3.9.7) allows authentication bypass and full account takeover via an unbound session boolean flag in the phone verification flow — attackers can hijack any account, including administrators, on affected WooCommerce sites.
5
The TrueBooker WordPress plugin before 1.2.4 fails to validate account ownership during password resets, letting unauthenticated attackers set an arbitrary password on any account including site administrators; a proof-of-concept already exists, making exploitation accessible.
6
Hypequery's ClickHouse semantic layer (before 2.0.2) fails to escape backslashes in parameter substitution, enabling SQL injection through attacker-controlled query parameters — any application exposing hypequery queries to user input is at risk of data extraction or manipulation.
7
IBM WebSphere Application Server 8.5 and 9.0 contains a broken access control and privilege escalation flaw in the administrative console, potentially allowing lower-privileged users to gain administrative control over the application server environment.
8
A pre-authentication unsafe deserialization vulnerability in IBM WebSphere Application Server 8.5 and 9.0 traditional allows remote attackers to bypass authentication or execute arbitrary code without credentials — this is a critical, externally exploitable flaw requiring immediate patching.
9
Apache Axis2/Java through 2.0.0 is vulnerable to unauthenticated remote code execution via a crafted serialized Java object delivered to the Tribes clustering port — the attack surface is limited to deployments with Tribes clustering explicitly enabled, but those environments should treat this as a critical emergency.
10
An authenticated SQL injection in the Giving Reports functionality of Ellucian Advance Web and Legacy Advance affects all versions, allowing attackers with valid credentials to extract sensitive data from the underlying database — a significant risk for higher education institutions relying on this platform.
Ransomware today
Ransomware activity recently targeting Brazil has been notably intense. Section9 has emerged as a particularly active group, claiming victims across multiple sectors including financial services, technology, agriculture, and others. Global Secret Group hit Sinop Energia in the energy sector and SPDM in healthcare, while arcusmedia claimed Power Moendas and blackwater targeted msgas.com.br in the energy and utilities space. Over the past 30 days, the most active groups targeting Brazilian organizations include lockbit5, lockbit3, ransomhub, thegentlemen, 8base, and arcusmedia, collectively representing a sustained and broad campaign against the country's private and public sectors.
********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 20
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are attributed to these groups at this time, their active monitoring status indicates potential ongoing reconnaissance or unreported activity — defenders should treat their presence on threat intelligence radars as a signal to review exposure.
Brazil focus
Brazil continues to be heavily targeted by ransomware operators. Recent victims span a broad range of sectors: Sinop Energia (energy and utilities, hit by Global Secret Group), SPDM (healthcare, Global Secret Group), and multiple organizations in financial services, technology, agriculture, and others attributed to Section9. The diversity of sectors and the volume of Brazilian targets in recent days underscore that no industry vertical in Brazil should consider itself outside the crosshairs of these groups.
******.com.brSection9 · Other
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
******.net.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Prioritize patching IBM WebSphere Application Server (CVE-2026-14512 and CVE-2026-14446), Apache Axis2/Java (CVE-2026-66713), and the Balbooa Forms Joomla extension (CVE-2026-65880) immediately, as these combine high technical severity with broad deployment bases. WordPress site operators running SMS Alert or TrueBooker plugins should update or disable those plugins without delay given the account takeover risks.
Even on a calm day, the combination of multiple CVSS 10.0 vulnerabilities and active ransomware campaigns targeting diverse sectors makes it essential to continuously validate your own attack surface rather than relying on the absence of confirmed exploits as a measure of safety.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →