Daily briefing · July 29, 2026

Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEs

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA

July 29, 2026 carries an ATTENTION-level verdict: three vulnerabilities are confirmed under active exploitation, two of which were flagged by VulnCheck before CISA could officially list them, signaling real-world attacker activity ahead of the public disclosure curve. The day's most urgent item is a Cisco Secure Firewall Management Center flaw with hardcoded credentials now on the CISA KEV list, while a devastating four-CVE cluster in the Joomla Gridbox extension — including CVSS 10.0 privilege escalation, account takeover, and arbitrary password reset — creates a chained path from unauthenticated access straight to remote code execution. Defenders running Joomla with Gridbox or managing Cisco FMC infrastructure should treat today as a patch-now situation.

Today’s brief
  • Cisco FMC hardcoded credentials (CVE-2026-20316) confirmed in active exploitation — CISA KEV listed, patch immediately.
  • Joomla Gridbox extension hit by four critical CVEs (65883–65888 range), enabling unauthenticated account creation, RCE, and full account takeover when chained.
  • VulnCheck detected two Gridbox flaws in active exploitation BEFORE CISA confirmation — a leading indicator that attackers are already moving.
  • Adobe Campaign Classic and flyto-core also carry CVSS 10.0 flaws with no user interaction required — widen your patch scope beyond the headline items.
42
critical
3
Actively exploited
2
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-20316KEVMEDIUM 5.3affects Cisco Secure Firewall Management Center (FMC)
A hardcoded low-privileged credential in Cisco Secure Firewall Management Center allows any unauthenticated remote attacker to log in and access sensitive data — now confirmed in active exploitation and listed on the CISA KEV. The static credential nature means no brute-force is needed; any attacker with the credential string can walk in immediately.
2
CVE-2026-65884◆ VulnCheckCVSS 10affects Gridbox extension for Joomla
This CVSS 10.0 flaw in Gridbox for Joomla (before 2.20.2) lets unauthenticated actors self-register accounts with administrator-level permissions by supplying controlled usergroup IDs during registration — VulnCheck observed exploitation before any official CISA listing. It serves as the unauthenticated entry point for the full Gridbox attack chain.
3
CVE-2026-65885◆ VulnCheckCVSS 9.4affects Gridbox extension for Joomla
Authenticated arbitrary file upload in Gridbox before 2.20.2 becomes a full remote code execution primitive when combined with CVE-2026-65884, since an attacker can first create an admin account and then upload a malicious file — VulnCheck flagged this pair in the wild ahead of CISA. The chained exploit effectively gives any internet-facing Joomla site running Gridbox an unauthenticated RCE exposure.
4
CVE-2026-48449CVSS 10affects Adobe Campaign Classic
Adobe Campaign Classic is affected by an incorrect authorization vulnerability (CVSS 10.0) that enables arbitrary code execution in the context of the current user with no user interaction required and with changed scope. Organizations running ACC in marketing or data pipeline workflows should prioritize patching given the no-interaction requirement.
5
CVE-2026-67429CVSS 10affects flyto-core
The flyto-core automation kernel before version 2.26.6 allows attacker-controlled output paths to bypass sandbox confinement, enabling arbitrary file writes across any filesystem path the process can reach. In AI-agent or automation workflows where this kernel is used, exploitation could result in persistent backdoors or configuration tampering.
6
CVE-2026-16326CVSS 10affects Tooling
consul-mcp-server versions 0.1.0 through 0.1.3 fail to isolate session state in stateless mode, allowing one client's Consul authentication token to bleed into subsequent requests from other clients. In multi-tenant or shared service mesh environments, this could allow lateral movement or unauthorized access to Consul-managed infrastructure.
7
CVE-2026-54735CVSS 10affects prebid-server
Prebid Server before 4.4.0 performs insufficient validation of host and subdomain values in bidder adapter URL construction, enabling crafted bid request parameters to redirect server-side requests to unintended destinations — a server-side request forgery class vulnerability with CVSS 10.0. Ad-tech infrastructure operators should treat this as a high-priority update given the external-facing nature of real-time bidding systems.
8
CVE-2026-65888CVSS 10affects Gridbox extension for Joomla
The socialLogin method in Gridbox for Joomla (before 2.20.2) allows unauthenticated actors to authenticate as any arbitrary user on the site, representing a complete account takeover primitive. Combined with the other Gridbox CVEs published today, this makes the extension one of the most dangerous Joomla components currently in circulation.
9
CVE-2026-65887CVSS 10affects Gridbox extension for Joomla
An unauthenticated arbitrary password reset flaw in Gridbox before 2.20.2 allows attackers to reset credentials for any account — excluding super admins — and then log in as those users. Sites relying on Gridbox for user management should assume all non-superadmin accounts are at risk until the patch is applied.
10
CVE-2026-65883CVSS 10affects Aimy Captcha-Less Form Guard plugin for Joomla
The Aimy Captcha-Less Form Guard Joomla plugin versions 18.0 through 20.0 contains a PHP object injection vulnerability triggered by a forged clfgd field, leading directly to remote code execution. As a captcha plugin typically exposed to all visitors, the unauthenticated attack surface is broad across any Joomla site running the affected versions.
Ransomware today

Ransomware activity targeting Brazilian organizations has been intense in the recent period, with Global Secret Group and Section9 emerging as the most active threat actors. Global Secret Group has claimed attacks against SPDM (Healthcare) and Sinop Energia (Energy & Utilities), while Section9 has struck multiple Brazilian organizations across Financial Services, Technology, Agriculture, and other sectors. Among the top groups active over the last 30 days, lockbit5 leads with 23 Brazilian victims, followed by Section9 (6), incransom (4), Global Secret Group (4), Qilin (3), and Deadlock (3).

SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.com.br BRSection9 · Financial Services
Sinop Energia BRGlobal Secret Group · Energy & Utilities
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
Power Moendas BRarcusmedia · Other
********.com.br BRSection9
SPDM BRGlobal Secret Group · Healthcare
*****.ind.br BRSection9 · Agriculture and Food Production
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs

Several threat actors and APT-linked groups are currently active or have recently updated their infrastructure, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no specific victim attributions have been confirmed for these groups at this time, their presence in threat intelligence feeds indicates ongoing reconnaissance or operational readiness. Defenders should monitor for indicators associated with these actors, particularly in sectors targeted by the ransomware groups active in the same period.

Brazil focus

Brazil is facing a concentrated ransomware campaign, with organizations across Healthcare, Energy, Financial Services, Technology, and Agriculture confirmed as recent victims. Named targets include SPDM (Healthcare) and Sinop Energia (Energy & Utilities), both claimed by Global Secret Group, alongside multiple .com.br, .net.br, and .ind.br domains attributed to Section9. The volume and sector diversity of Brazilian victims — combined with the high concentration of Joomla-based websites in the country's SMB market — makes today's Joomla Gridbox and Aimy Captcha-Less CVEs particularly relevant for the Brazilian threat landscape.

Sinop EnergiaGlobal Secret Group · Energy & Utilities
SPDMGlobal Secret Group · Healthcare
****.com.brSection9 · Technology
********.com.brSection9
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
******.net.brSection9 · Financial Services
Today’s recommendation: Organizations should immediately patch Cisco FMC to eliminate the hardcoded credential exposure and remove or update the Joomla Gridbox extension to version 2.20.2 or later — treating the four-CVE cluster as a single chained RCE threat rather than isolated issues. Simultaneously, apply available updates for Adobe Campaign Classic, flyto-core, consul-mcp-server, and Prebid Server, prioritizing any instance exposed to untrusted network input.
With multiple no-interaction CVSS 10.0 vulnerabilities and confirmed active exploitation in the wild today, the critical question for every defender is whether their own attack surface includes any of these components — and the only reliable answer comes from actively testing and validating exposure, not assuming inventory lists are complete.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share