Daily briefing · July 30, 2026

32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 30, 2026 closes as a calm day from an exploitation standpoint — no vulnerabilities confirmed weaponized, no active exploitation recorded, and no VulnCheck pre-CISA signals. Despite the quiet threat landscape, 278 new CVEs were published including 32 critical-severity entries, with several affecting widely deployed enterprise platforms such as Azure Cosmos DB, IBM HMC, IBM webMethods, and Rocket.Chat. Defenders should not be lulled by the lack of active exploitation: several of these flaws are unauthenticated RCE or authentication bypass issues with the structural profile that attackers routinely prioritize.

Today’s brief
  • 32 critical CVEs published today — no active exploitation confirmed, but several carry high weaponization potential
  • Azure Cosmos DB (CVSS 10.0) and IBM HMC/webMethods (CVSS 9.8) top the list with unauthenticated RCE or code execution primitives
  • Rocket.Chat SAML SSO flaw allows identity forging by any attacker holding a valid IdP-signed document — patch to fixed versions immediately
  • Brazil-focused ransomware activity intensifies: Global Secret Group hit healthcare (SPDM) and energy (Sinop Energia) targets in recent days
32
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-66803CVSS 10affects Azure Cosmos DB
A CVSS 10.0 improper access control in Azure Cosmos DB allows an unauthenticated network attacker to execute arbitrary code — the maximum severity score reflects the combination of no authentication required and broad cloud exposure, making this the top patching priority of the day.
2
CVE-2026-58046CVSS 9.9affects Plesk
A SQL injection flaw in the Plesk XML-RPC API can be triggered by any low-privileged remote authenticated user, leading to full panel compromise and arbitrary database read; the low authentication bar dramatically widens the attacker pool for shared hosting environments.
3
CVE-2026-12946CVSS 9.9affects Langflow OSS
IBM Langflow OSS versions 1.0.0 through 1.10.0 allow a remote attacker to inject and execute arbitrary code due to improper control of user-supplied input — any internet-exposed Langflow instance should be treated as compromised until patched.
4
CVE-2026-13435CVSS 9.9affects Langflow OSS
A companion flaw to CVE-2026-12946, this improper input validation in Langflow OSS's PythonREPL sandbox (through 1.10.1) means the sandboxing mechanism cannot be trusted; both Langflow CVEs should be remediated together as a single upgrade.
5
CVE-2026-16610CVSS 9.8affects Admin and Site Enhancements (ASE) Pro
The Admin and Site Enhancements (ASE) Pro WordPress plugin (up to 8.9.0) exposes an unauthenticated RCE path through a publicly accessible save handler with no authentication check, allowing any visitor to abuse the repeater field logic to execute server-side code.
6
CVE-2026-58066CVSS 9.8affects Rocket.Chat
Rocket.Chat's SAML SSO implementation before several patched versions validated XML signatures but failed to bind them to specific assertions, enabling an attacker to wrap forged identity attributes around any legitimate IdP signature and authenticate as an arbitrary user — a classic XML signature wrapping attack with broad impact in SSO-federated deployments.
7
CVE-2026-68503CVSS 9.8affects LazyOwn
LazyOwn RedTeam Framework ships hardcoded default C2 credentials ('LazyOwn'/'LazyOwn') that are passed unchanged to HTTP Basic Auth, meaning any attacker with network reach to the C2 dashboard can authenticate with operator-level privileges — a critical misconfiguration-as-vulnerability in a tool designed for offensive operations.
8
CVE-2026-68502CVSS 9.8affects LazyOwn
A separate but equally severe flaw in LazyOwn registers an unauthenticated Socket.IO handler that passes untrusted input directly to subprocess.call with shell=True, enabling fully unauthenticated remote code execution on the C2 server — red teams running unpatched LazyOwn instances are exposing their own infrastructure.
9
CVE-2026-12943CVSS 9.8affects HMC V10.3.1050.0
IBM HMC versions spanning V10.3.1050.0 through V11.1.1112.0 allow an unauthenticated user to execute arbitrary commands with elevated privileges due to improper input validation — IBM Power management planes are high-value targets and this entry-level access path warrants emergency patching.
10
CVE-2026-12118CVSS 9.8affects webMethods Integration (on prem)
IBM webMethods Integration (on-premises) 10.11 and 10.15 are vulnerable to unauthenticated RCE via deserialization of untrusted data — Java deserialization vulnerabilities in enterprise integration middleware have historically been weaponized rapidly, and this should be treated as high urgency pending proof-of-concept availability.
Ransomware today

The Global Secret Group ransomware gang has recently claimed two Brazilian victims: SPDM, a healthcare organization, and Sinop Energia, an energy and utilities company. Over the past 30 days, Global Secret Group has recorded four attacks, all targeting Brazilian entities, while lockbit5 leads overall activity with 23 confirmed victims — all also in Brazil — underscoring a sustained and concentrated focus on the Brazilian market by multiple ransomware operators.

SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs

Several threat actor profiles have surfaced or been updated in recent monitoring, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. None of these groups have publicly confirmed victims in the current data set, but their active tracking status suggests ongoing reconnaissance or unreported intrusion activity that defenders should factor into threat modeling.

Brazil focus

Brazil is seeing disproportionate ransomware pressure relative to global averages. In the past 30 days, Section9 has hit at least six Brazilian organizations spanning financial services, technology, agriculture, and other sectors — most victims identified only by masked domain names. Combined with Global Secret Group's confirmed attacks on SPDM and Sinop Energia, critical infrastructure and healthcare in Brazil are facing a materially elevated threat environment.

SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
******.com.brSection9 · Other
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
****.com.brSection9 · Technology
********.com.brSection9
Today’s recommendation: Prioritize patching CVE-2026-66803 (Azure Cosmos DB), CVE-2026-12943 (IBM HMC), and CVE-2026-12118 (IBM webMethods) as emergency items given their unauthenticated RCE profiles; simultaneously, upgrade Rocket.Chat to a patched SAML-fixed release and enforce credential rotation on any deployed LazyOwn instances.
Even on a day without confirmed active exploitation, the structural severity of today's vulnerabilities is a direct reminder that the window between publication and weaponization is shrinking — validating your actual exposure to each affected platform is the only way to know whether today's calm is relevant to your environment.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share