Daily briefing · July 31, 2026
Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 31, 2026 registered no actively exploited vulnerabilities and no weaponized exploits, placing the day firmly in the calm category — but the vulnerability landscape is anything but quiet. Fifteen critical CVEs were published in a single day, spanning hard-coded credentials, arbitrary file uploads, SQL injection, and code injection across widely deployed platforms. Defenders should treat this publication wave as a patching window that will close fast, given the historical pace at which such classes of bugs get weaponized.
Today’s brief
- No active exploitation (KEV) or weaponized exploits recorded today, but 15 critical CVEs published demand immediate attention
- CVE-2026-18452 scores a perfect CVSS 10.0: hard-coded API keys in DMS+ allow unauthenticated full device takeover
- WordPress, cPanel, pgAdmin 4, Logsign SIEM, and Pterodactyl Wings are all among the affected platforms — broad enterprise and hosting exposure
- Brazil faces sustained ransomware pressure: thegentlemen and Global Secret Group hit government, healthcare, energy, and services sectors
Critical highlights
1
A CVSS 10.0 perfect score driven by hard-coded API credentials in DMS+ (Non-Mobile): unauthenticated remote attackers can take full control of every installed device. Any internet-facing DMS+ deployment should be considered compromised until patched or isolated.
2
In Pterodactyl Wings before 1.12.3, low-privileged users can read daemon tokens and Docker registry secrets via template placeholder injection, effectively escalating to daemon-level access. Patch to 1.12.3 immediately in any multi-tenant game server environment.
3
CVE-2026-14483CVSS 9.8affects Realtyna Organic IDX plugin + WPL Real Estate The Realtyna Organic IDX + WPL Real Estate WordPress plugin (up to 5.2.0) allows arbitrary file upload through a publicly accessible endpoint protected only by static, shared API credentials. An unauthenticated attacker can upload and execute malicious files on any unpatched WordPress installation.
4
CodeIgniter4 before 4.7.4 fails to enforce safe file extensions in its upload validation rules, enabling remote attackers to upload executable content to web-accessible directories. Applications that preserve client-supplied filenames are directly exposed to remote code execution.
5
The ShopMonitor.io WordPress plugin before 1.2.0 lets unauthenticated attackers hijack outbound emails — including administrator password-reset messages — by spoofing trusted request headers, enabling full account takeover. A proof-of-concept is already known, raising the urgency for immediate removal or update.
6
Logsign SIEM before 6.4.108 contains a code injection vulnerability that allows remote attackers to execute arbitrary code on the SIEM appliance itself — a particularly severe risk given that SIEMs sit at the heart of security monitoring infrastructure.
7
The vault-secrets-webhook for Kubernetes before 1.23.1 can be abused via user-controlled annotations to perform unauthorized Vault operations or leak service account JWTs, undermining the secret injection model in affected clusters. Kubernetes environments using this webhook for secrets management should upgrade immediately.
8
CodeIgniter4 versions 4.3.0 through 4.7.3 allow SQL injection via the deleteBatch() method, where bound values from where() conditions are substituted into SQL with escape flags ignored. Any application using deleteBatch() with user-controlled input is at direct risk of data compromise.
9
A SQL injection flaw in cPanel's database-rename functionality allows execution of SQL in root context, meaning an attacker with access to the rename feature could achieve full database server compromise. Shared hosting providers running cPanel are especially exposed.
10
pgAdmin 4's Import/Export Data tool improperly interpolates user-supplied SQL into a Jinja template passed to psql, enabling command injection by any user with the commonly granted tools_import_export_data permission. This is a low-barrier privilege escalation path in shared pgAdmin deployments.
Ransomware today
Ransomware activity targeting Brazil remains notably elevated. Recently, thegentlemen claimed the Municipal Chamber of Serra and CRB group (Professional Services), while Global Secret Group targeted SPDM (Healthcare) and Sinop Energia (Energy & Utilities). Over the past 30 days, lockbit5 leads overall activity with 23 victims — all in Brazil — followed by Section9, incransom, Global Secret Group, qilin, and Deadlock, painting a picture of sustained, coordinated pressure across critical Brazilian sectors.
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actor groups are being tracked with updated activity signals, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are currently attributed to these actors in this cycle, their monitoring status indicates intelligence services are observing new infrastructure, tooling updates, or threat posturing that warrants continued attention from defenders.
Brazil focus
Brazil is under sustained ransomware siege across multiple critical sectors. Recent victims include the Municipal Chamber of Serra (government), SPDM (healthcare), Sinop Energia (energy), CRB group (professional services), and additional targets in financial services and agriculture claimed by Section9. The concentration of attacks across public administration, healthcare, and utilities underscores that Brazilian organizations of all sizes and verticals remain high-priority targets for multiple active ransomware groups.
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.com.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
Today’s recommendation: Prioritize patching CVE-2026-18452 (DMS+), CVE-2026-52855 (Pterodactyl Wings), CVE-2026-14483 (WordPress WPL), and CVE-2026-17561 (Logsign SIEM) immediately, as all combine critical CVSS scores with unauthenticated or low-barrier attack paths. For CodeIgniter4 and pgAdmin 4 flaws, audit applications for use of deleteBatch() with user input and restrict the Import/Export tool to trusted users pending upgrade.
Even on a day without confirmed active exploitation, the sheer breadth of critical attack surfaces disclosed today makes it essential to continuously map and validate your own exposure before attackers do.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →