Daily briefing · July 29, 2026
Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEs
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA
July 29, 2026 carries an ATTENTION-level verdict: three vulnerabilities are confirmed under active exploitation, two of which were flagged by VulnCheck before CISA could officially list them, signaling real-world attacker activity ahead of the public disclosure curve. The day's most urgent item is a Cisco Secure Firewall Management Center flaw with hardcoded credentials now on the CISA KEV list, while a devastating four-CVE cluster in the Joomla Gridbox extension — including CVSS 10.0 privilege escalation, account takeover, and arbitrary password reset — creates a chained path from unauthenticated access straight to remote code execution. Defenders running Joomla with Gridbox or managing Cisco FMC infrastructure should treat today as a patch-now situation.
Today’s brief
- Cisco FMC hardcoded credentials (CVE-2026-20316) confirmed in active exploitation — CISA KEV listed, patch immediately.
- Joomla Gridbox extension hit by four critical CVEs (65883–65888 range), enabling unauthenticated account creation, RCE, and full account takeover when chained.
- VulnCheck detected two Gridbox flaws in active exploitation BEFORE CISA confirmation — a leading indicator that attackers are already moving.
- Adobe Campaign Classic and flyto-core also carry CVSS 10.0 flaws with no user interaction required — widen your patch scope beyond the headline items.
Critical highlights
1
CVE-2026-20316KEVMEDIUM 5.3affects Cisco Secure Firewall Management Center (FMC) A hardcoded low-privileged credential in Cisco Secure Firewall Management Center allows any unauthenticated remote attacker to log in and access sensitive data — now confirmed in active exploitation and listed on the CISA KEV. The static credential nature means no brute-force is needed; any attacker with the credential string can walk in immediately.
2
This CVSS 10.0 flaw in Gridbox for Joomla (before 2.20.2) lets unauthenticated actors self-register accounts with administrator-level permissions by supplying controlled usergroup IDs during registration — VulnCheck observed exploitation before any official CISA listing. It serves as the unauthenticated entry point for the full Gridbox attack chain.
3
Authenticated arbitrary file upload in Gridbox before 2.20.2 becomes a full remote code execution primitive when combined with CVE-2026-65884, since an attacker can first create an admin account and then upload a malicious file — VulnCheck flagged this pair in the wild ahead of CISA. The chained exploit effectively gives any internet-facing Joomla site running Gridbox an unauthenticated RCE exposure.
4
Adobe Campaign Classic is affected by an incorrect authorization vulnerability (CVSS 10.0) that enables arbitrary code execution in the context of the current user with no user interaction required and with changed scope. Organizations running ACC in marketing or data pipeline workflows should prioritize patching given the no-interaction requirement.
5
The flyto-core automation kernel before version 2.26.6 allows attacker-controlled output paths to bypass sandbox confinement, enabling arbitrary file writes across any filesystem path the process can reach. In AI-agent or automation workflows where this kernel is used, exploitation could result in persistent backdoors or configuration tampering.
6
consul-mcp-server versions 0.1.0 through 0.1.3 fail to isolate session state in stateless mode, allowing one client's Consul authentication token to bleed into subsequent requests from other clients. In multi-tenant or shared service mesh environments, this could allow lateral movement or unauthorized access to Consul-managed infrastructure.
7
Prebid Server before 4.4.0 performs insufficient validation of host and subdomain values in bidder adapter URL construction, enabling crafted bid request parameters to redirect server-side requests to unintended destinations — a server-side request forgery class vulnerability with CVSS 10.0. Ad-tech infrastructure operators should treat this as a high-priority update given the external-facing nature of real-time bidding systems.
8
The socialLogin method in Gridbox for Joomla (before 2.20.2) allows unauthenticated actors to authenticate as any arbitrary user on the site, representing a complete account takeover primitive. Combined with the other Gridbox CVEs published today, this makes the extension one of the most dangerous Joomla components currently in circulation.
9
An unauthenticated arbitrary password reset flaw in Gridbox before 2.20.2 allows attackers to reset credentials for any account — excluding super admins — and then log in as those users. Sites relying on Gridbox for user management should assume all non-superadmin accounts are at risk until the patch is applied.
10
CVE-2026-65883CVSS 10affects Aimy Captcha-Less Form Guard plugin for Joomla The Aimy Captcha-Less Form Guard Joomla plugin versions 18.0 through 20.0 contains a PHP object injection vulnerability triggered by a forged clfgd field, leading directly to remote code execution. As a captcha plugin typically exposed to all visitors, the unauthenticated attack surface is broad across any Joomla site running the affected versions.
Ransomware today
Ransomware activity targeting Brazilian organizations has been intense in the recent period, with Global Secret Group and Section9 emerging as the most active threat actors. Global Secret Group has claimed attacks against SPDM (Healthcare) and Sinop Energia (Energy & Utilities), while Section9 has struck multiple Brazilian organizations across Financial Services, Technology, Agriculture, and other sectors. Among the top groups active over the last 30 days, lockbit5 leads with 23 Brazilian victims, followed by Section9 (6), incransom (4), Global Secret Group (4), Qilin (3), and Deadlock (3).
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.com.br BRSection9 · Financial Services
Sinop Energia BRGlobal Secret Group · Energy & Utilities
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
Power Moendas BRarcusmedia · Other
********.com.br BRSection9
SPDM BRGlobal Secret Group · Healthcare
*****.ind.br BRSection9 · Agriculture and Food Production
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actors and APT-linked groups are currently active or have recently updated their infrastructure, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no specific victim attributions have been confirmed for these groups at this time, their presence in threat intelligence feeds indicates ongoing reconnaissance or operational readiness. Defenders should monitor for indicators associated with these actors, particularly in sectors targeted by the ransomware groups active in the same period.
Brazil focus
Brazil is facing a concentrated ransomware campaign, with organizations across Healthcare, Energy, Financial Services, Technology, and Agriculture confirmed as recent victims. Named targets include SPDM (Healthcare) and Sinop Energia (Energy & Utilities), both claimed by Global Secret Group, alongside multiple .com.br, .net.br, and .ind.br domains attributed to Section9. The volume and sector diversity of Brazilian victims — combined with the high concentration of Joomla-based websites in the country's SMB market — makes today's Joomla Gridbox and Aimy Captcha-Less CVEs particularly relevant for the Brazilian threat landscape.
Sinop EnergiaGlobal Secret Group · Energy & Utilities
SPDMGlobal Secret Group · Healthcare
****.com.brSection9 · Technology
********.com.brSection9
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
******.net.brSection9 · Financial Services
Today’s recommendation: Organizations should immediately patch Cisco FMC to eliminate the hardcoded credential exposure and remove or update the Joomla Gridbox extension to version 2.20.2 or later — treating the four-CVE cluster as a single chained RCE threat rather than isolated issues. Simultaneously, apply available updates for Adobe Campaign Classic, flyto-core, consul-mcp-server, and Prebid Server, prioritizing any instance exposed to untrusted network input.
With multiple no-interaction CVSS 10.0 vulnerabilities and confirmed active exploitation in the wild today, the critical question for every defender is whether their own attack surface includes any of these components — and the only reliable answer comes from actively testing and validating exposure, not assuming inventory lists are complete.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →