Daily briefing · July 30, 2026
32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 30, 2026 closes as a calm day from an exploitation standpoint — no vulnerabilities confirmed weaponized, no active exploitation recorded, and no VulnCheck pre-CISA signals. Despite the quiet threat landscape, 278 new CVEs were published including 32 critical-severity entries, with several affecting widely deployed enterprise platforms such as Azure Cosmos DB, IBM HMC, IBM webMethods, and Rocket.Chat. Defenders should not be lulled by the lack of active exploitation: several of these flaws are unauthenticated RCE or authentication bypass issues with the structural profile that attackers routinely prioritize.
Today’s brief
- 32 critical CVEs published today — no active exploitation confirmed, but several carry high weaponization potential
- Azure Cosmos DB (CVSS 10.0) and IBM HMC/webMethods (CVSS 9.8) top the list with unauthenticated RCE or code execution primitives
- Rocket.Chat SAML SSO flaw allows identity forging by any attacker holding a valid IdP-signed document — patch to fixed versions immediately
- Brazil-focused ransomware activity intensifies: Global Secret Group hit healthcare (SPDM) and energy (Sinop Energia) targets in recent days
Critical highlights
1
A CVSS 10.0 improper access control in Azure Cosmos DB allows an unauthenticated network attacker to execute arbitrary code — the maximum severity score reflects the combination of no authentication required and broad cloud exposure, making this the top patching priority of the day.
2
A SQL injection flaw in the Plesk XML-RPC API can be triggered by any low-privileged remote authenticated user, leading to full panel compromise and arbitrary database read; the low authentication bar dramatically widens the attacker pool for shared hosting environments.
3
IBM Langflow OSS versions 1.0.0 through 1.10.0 allow a remote attacker to inject and execute arbitrary code due to improper control of user-supplied input — any internet-exposed Langflow instance should be treated as compromised until patched.
4
A companion flaw to CVE-2026-12946, this improper input validation in Langflow OSS's PythonREPL sandbox (through 1.10.1) means the sandboxing mechanism cannot be trusted; both Langflow CVEs should be remediated together as a single upgrade.
5
The Admin and Site Enhancements (ASE) Pro WordPress plugin (up to 8.9.0) exposes an unauthenticated RCE path through a publicly accessible save handler with no authentication check, allowing any visitor to abuse the repeater field logic to execute server-side code.
6
Rocket.Chat's SAML SSO implementation before several patched versions validated XML signatures but failed to bind them to specific assertions, enabling an attacker to wrap forged identity attributes around any legitimate IdP signature and authenticate as an arbitrary user — a classic XML signature wrapping attack with broad impact in SSO-federated deployments.
7
LazyOwn RedTeam Framework ships hardcoded default C2 credentials ('LazyOwn'/'LazyOwn') that are passed unchanged to HTTP Basic Auth, meaning any attacker with network reach to the C2 dashboard can authenticate with operator-level privileges — a critical misconfiguration-as-vulnerability in a tool designed for offensive operations.
8
A separate but equally severe flaw in LazyOwn registers an unauthenticated Socket.IO handler that passes untrusted input directly to subprocess.call with shell=True, enabling fully unauthenticated remote code execution on the C2 server — red teams running unpatched LazyOwn instances are exposing their own infrastructure.
9
IBM HMC versions spanning V10.3.1050.0 through V11.1.1112.0 allow an unauthenticated user to execute arbitrary commands with elevated privileges due to improper input validation — IBM Power management planes are high-value targets and this entry-level access path warrants emergency patching.
10
IBM webMethods Integration (on-premises) 10.11 and 10.15 are vulnerable to unauthenticated RCE via deserialization of untrusted data — Java deserialization vulnerabilities in enterprise integration middleware have historically been weaponized rapidly, and this should be treated as high urgency pending proof-of-concept availability.
Ransomware today
The Global Secret Group ransomware gang has recently claimed two Brazilian victims: SPDM, a healthcare organization, and Sinop Energia, an energy and utilities company. Over the past 30 days, Global Secret Group has recorded four attacks, all targeting Brazilian entities, while lockbit5 leads overall activity with 23 confirmed victims — all also in Brazil — underscoring a sustained and concentrated focus on the Brazilian market by multiple ransomware operators.
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actor profiles have surfaced or been updated in recent monitoring, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. None of these groups have publicly confirmed victims in the current data set, but their active tracking status suggests ongoing reconnaissance or unreported intrusion activity that defenders should factor into threat modeling.
Brazil focus
Brazil is seeing disproportionate ransomware pressure relative to global averages. In the past 30 days, Section9 has hit at least six Brazilian organizations spanning financial services, technology, agriculture, and other sectors — most victims identified only by masked domain names. Combined with Global Secret Group's confirmed attacks on SPDM and Sinop Energia, critical infrastructure and healthcare in Brazil are facing a materially elevated threat environment.
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
******.com.brSection9 · Other
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
********.com.brSection9
Today’s recommendation: Prioritize patching CVE-2026-66803 (Azure Cosmos DB), CVE-2026-12943 (IBM HMC), and CVE-2026-12118 (IBM webMethods) as emergency items given their unauthenticated RCE profiles; simultaneously, upgrade Rocket.Chat to a patched SAML-fixed release and enforce credential rotation on any deployed LazyOwn instances.
Even on a day without confirmed active exploitation, the structural severity of today's vulnerabilities is a direct reminder that the window between publication and weaponization is shrinking — validating your actual exposure to each affected platform is the only way to know whether today's calm is relevant to your environment.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →