Daily briefing · July 31, 2026
Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 31, 2026 registered no actively exploited vulnerabilities and no weaponized exploits, placing the day firmly in the calm category — but the vulnerability landscape is anything but quiet. Fifteen critical CVEs were published in a single day, spanning hard-coded credentials, arbitrary file uploads, SQL injection, and code injection across widely deployed platforms. Defenders should treat this publication wave as a patching window that will close fast, given the historical pace at which such classes of bugs get weaponized.
Today’s brief
- No active exploitation (KEV) or weaponized exploits recorded today, but 15 critical CVEs published demand immediate attention
- CVE-2026-18452 scores a perfect CVSS 10.0: hard-coded API keys in DMS+ allow unauthenticated full device takeover
- WordPress, cPanel, pgAdmin 4, Logsign SIEM, and Pterodactyl Wings are all among the affected platforms — broad enterprise and hosting exposure
- Brazil faces sustained ransomware pressure: thegentlemen and Global Secret Group hit government, healthcare, energy, and services sectors
Critical highlights
1
A CVSS 10.0 perfect score driven by hard-coded API credentials in DMS+ (Non-Mobile): unauthenticated remote attackers can take full control of every installed device. Any internet-facing DMS+ deployment should be considered compromised until patched or isolated.
2
In Pterodactyl Wings before 1.12.3, low-privileged users can read daemon tokens and Docker registry secrets via template placeholder injection, effectively escalating to daemon-level access. Patch to 1.12.3 immediately in any multi-tenant game server environment.
3
CVE-2026-14483CVSS 9.8affects Realtyna Organic IDX plugin + WPL Real Estate The Realtyna Organic IDX + WPL Real Estate WordPress plugin (up to 5.2.0) allows arbitrary file upload through a publicly accessible endpoint protected only by static, shared API credentials. An unauthenticated attacker can upload and execute malicious files on any unpatched WordPress installation.
4
CodeIgniter4 before 4.7.4 fails to enforce safe file extensions in its upload validation rules, enabling remote attackers to upload executable content to web-accessible directories. Applications that preserve client-supplied filenames are directly exposed to remote code execution.
5
The ShopMonitor.io WordPress plugin before 1.2.0 lets unauthenticated attackers hijack outbound emails — including administrator password-reset messages — by spoofing trusted request headers, enabling full account takeover. A proof-of-concept is already known, raising the urgency for immediate removal or update.
6
Logsign SIEM before 6.4.108 contains a code injection vulnerability that allows remote attackers to execute arbitrary code on the SIEM appliance itself — a particularly severe risk given that SIEMs sit at the heart of security monitoring infrastructure.
7
The vault-secrets-webhook for Kubernetes before 1.23.1 can be abused via user-controlled annotations to perform unauthorized Vault operations or leak service account JWTs, undermining the secret injection model in affected clusters. Kubernetes environments using this webhook for secrets management should upgrade immediately.
8
CodeIgniter4 versions 4.3.0 through 4.7.3 allow SQL injection via the deleteBatch() method, where bound values from where() conditions are substituted into SQL with escape flags ignored. Any application using deleteBatch() with user-controlled input is at direct risk of data compromise.
9
A SQL injection flaw in cPanel's database-rename functionality allows execution of SQL in root context, meaning an attacker with access to the rename feature could achieve full database server compromise. Shared hosting providers running cPanel are especially exposed.
10
pgAdmin 4's Import/Export Data tool improperly interpolates user-supplied SQL into a Jinja template passed to psql, enabling command injection by any user with the commonly granted tools_import_export_data permission. This is a low-barrier privilege escalation path in shared pgAdmin deployments.
Ransomware today
Ransomware activity targeting Brazil remains notably elevated. Recently, thegentlemen claimed the Municipal Chamber of Serra and CRB group (Professional Services), while Global Secret Group targeted SPDM (Healthcare) and Sinop Energia (Energy & Utilities). Over the past 30 days, lockbit5 leads overall activity with 23 victims — all in Brazil — followed by Section9, incransom, Global Secret Group, qilin, and Deadlock, painting a picture of sustained, coordinated pressure across critical Brazilian sectors.
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actor groups are being tracked with updated activity signals, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are currently attributed to these actors in this cycle, their monitoring status indicates intelligence services are observing new infrastructure, tooling updates, or threat posturing that warrants continued attention from defenders.
Brazil focus
Brazil is under sustained ransomware siege across multiple critical sectors. Recent victims include the Municipal Chamber of Serra (government), SPDM (healthcare), Sinop Energia (energy), CRB group (professional services), and additional targets in financial services and agriculture claimed by Section9. The concentration of attacks across public administration, healthcare, and utilities underscores that Brazilian organizations of all sizes and verticals remain high-priority targets for multiple active ransomware groups.
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.com.brSection9 · Financial Services
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
Today’s recommendation: Prioritize patching CVE-2026-18452 (DMS+), CVE-2026-52855 (Pterodactyl Wings), CVE-2026-14483 (WordPress WPL), and CVE-2026-17561 (Logsign SIEM) immediately, as all combine critical CVSS scores with unauthenticated or low-barrier attack paths. For CodeIgniter4 and pgAdmin 4 flaws, audit applications for use of deleteBatch() with user input and restrict the Import/Export tool to trusted users pending upgrade.
Even on a day without confirmed active exploitation, the sheer breadth of critical attack surfaces disclosed today makes it essential to continuously map and validate your own exposure before attackers do.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →