Daily briefing · July 28, 2026
Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the List
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 28, 2026 recorded no actively exploited vulnerabilities and no weaponized exploits, placing it firmly in the calm category — but the day brought 253 new CVEs, 20 of them critical, demanding careful attention from defenders. Deserialization flaws and authentication bypass vulnerabilities dominate the highlights, with IBM WebSphere, Apache Axis2, and a Joomla extension carrying the highest risk profiles. While no active exploitation has been confirmed, the technical severity of several entries is high enough to treat them as urgent patching priorities.
Today’s brief
- No active exploitation or KEV entries today, but 20 critical CVEs published — calm does not mean safe.
- IBM WebSphere Application Server carries two CVSS 9.8 flaws: broken access control in the admin console and pre-authentication unsafe deserialization allowing RCE.
- Apache Axis2/Java deserialization (CVSS 9.8) and Balbooa Forms for Joomla unauthenticated RCE (CVSS 10.0) are high-priority patch targets.
- Brazil faces a wave of ransomware activity: Section9, Global Secret Group, and other groups have recently struck targets across energy, healthcare, financial services, and agriculture sectors.
Critical highlights
1
CVE-2026-11756CVSS 10affects Station Launcher App in 3DEXPERIENCE platform A CVSS 10.0 deserialization flaw in the Station Launcher App of Dassault's 3DEXPERIENCE platform allows unauthenticated remote code execution across releases R2023x through R2026x — a maximum-severity risk for enterprises running this PLM environment that should be patched immediately.
2
The terraform-mcp-server before 1.1.0 allows cross-tenant credential reuse in stateless HTTP transport mode, meaning one user's Terraform token could be leveraged to execute tool calls as another user — a critical supply chain and infrastructure automation risk in shared environments.
3
Unauthenticated remote code execution in the Balbooa Forms Joomla extension (before 2.4.3) stems from insecure form processing when a signature field type is present — any internet-facing Joomla site running this plugin should be considered fully compromised until patched.
4
CVE-2026-15014CVSS 9.8affects SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery The SMS Alert WordPress plugin (up to 3.9.7) allows authentication bypass and full account takeover via an unbound session boolean flag in the phone verification flow — attackers can hijack any account, including administrators, on affected WooCommerce sites.
5
The TrueBooker WordPress plugin before 1.2.4 fails to validate account ownership during password resets, letting unauthenticated attackers set an arbitrary password on any account including site administrators; a proof-of-concept already exists, making exploitation accessible.
6
Hypequery's ClickHouse semantic layer (before 2.0.2) fails to escape backslashes in parameter substitution, enabling SQL injection through attacker-controlled query parameters — any application exposing hypequery queries to user input is at risk of data extraction or manipulation.
7
IBM WebSphere Application Server 8.5 and 9.0 contains a broken access control and privilege escalation flaw in the administrative console, potentially allowing lower-privileged users to gain administrative control over the application server environment.
8
A pre-authentication unsafe deserialization vulnerability in IBM WebSphere Application Server 8.5 and 9.0 traditional allows remote attackers to bypass authentication or execute arbitrary code without credentials — this is a critical, externally exploitable flaw requiring immediate patching.
9
Apache Axis2/Java through 2.0.0 is vulnerable to unauthenticated remote code execution via a crafted serialized Java object delivered to the Tribes clustering port — the attack surface is limited to deployments with Tribes clustering explicitly enabled, but those environments should treat this as a critical emergency.
10
An authenticated SQL injection in the Giving Reports functionality of Ellucian Advance Web and Legacy Advance affects all versions, allowing attackers with valid credentials to extract sensitive data from the underlying database — a significant risk for higher education institutions relying on this platform.
Ransomware today
Ransomware activity recently targeting Brazil has been notably intense. Section9 has emerged as a particularly active group, claiming victims across multiple sectors including financial services, technology, agriculture, and others. Global Secret Group hit Sinop Energia in the energy sector and SPDM in healthcare, while arcusmedia claimed Power Moendas and blackwater targeted msgas.com.br in the energy and utilities space. Over the past 30 days, the most active groups targeting Brazilian organizations include lockbit5, lockbit3, ransomhub, thegentlemen, 8base, and arcusmedia, collectively representing a sustained and broad campaign against the country's private and public sectors.
********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 20
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are attributed to these groups at this time, their active monitoring status indicates potential ongoing reconnaissance or unreported activity — defenders should treat their presence on threat intelligence radars as a signal to review exposure.
Brazil focus
Brazil continues to be heavily targeted by ransomware operators. Recent victims span a broad range of sectors: Sinop Energia (energy and utilities, hit by Global Secret Group), SPDM (healthcare, Global Secret Group), and multiple organizations in financial services, technology, agriculture, and others attributed to Section9. The diversity of sectors and the volume of Brazilian targets in recent days underscore that no industry vertical in Brazil should consider itself outside the crosshairs of these groups.
******.com.brSection9 · Other
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
******.net.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Prioritize patching IBM WebSphere Application Server (CVE-2026-14512 and CVE-2026-14446), Apache Axis2/Java (CVE-2026-66713), and the Balbooa Forms Joomla extension (CVE-2026-65880) immediately, as these combine high technical severity with broad deployment bases. WordPress site operators running SMS Alert or TrueBooker plugins should update or disable those plugins without delay given the account takeover risks.
Even on a calm day, the combination of multiple CVSS 10.0 vulnerabilities and active ransomware campaigns targeting diverse sectors makes it essential to continuously validate your own attack surface rather than relying on the absence of confirmed exploits as a measure of safety.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →