Daily briefing · August 1, 2026
WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 1, 2026 brought a calm vulnerability landscape with no active exploitation or weaponized exploits confirmed, yet 15 critical-severity CVEs were published, demanding prompt attention from defenders. Leading the pack are two WordPress authentication bypass flaws and a cluster of critical FreeRDP and better-auth issues that could expose broad enterprise surfaces. While the threat level is measured, the density of authentication and memory-corruption vulnerabilities in widely deployed software warrants focused patching this week.
Today’s brief
- No CVEs in active exploitation (KEV) today, but 15 critical-severity vulnerabilities were published — patching remains urgent
- Two WordPress plugin auth bypasses (Single Sign On For TNG and WooCommerce Social Login) allow unauthenticated account takeover
- FreeRDP received three critical CVEs affecting heap integrity, WebSocket disclosure, and HTTP proxy header injection
- Brazil is actively targeted by ransomware: thegentlemen and Global Secret Group hit government, healthcare, and energy sectors recently
Critical highlights
1
A CVSS 9.8 unauthenticated password reset flaw in the Single Sign On For TNG WordPress plugin (≤2.0.0) allows any attacker to take over accounts without credentials — notably, a proof-of-concept was published the same day as disclosure, making rapid exploitation highly plausible.
2
The WooCommerce Social Login plugin (≤2.8.7) accepts Apple id_tokens without verifying JWT signatures, issuers, audiences, or expiry, effectively allowing anyone to forge an Apple identity and bypass authentication on WooCommerce stores.
3
better-auth (before 1.6.11) advertises the 'none' JWT algorithm and accepts plain PKCE by default in its OIDC and MCP plugins, enabling attackers to submit unsigned tokens or intercept authorization codes through algorithm negotiation abuse.
4
The @better-auth/scim plugin fails to prevent SCIM token issuance for provider IDs already held by existing SSO, SAML, or OAuth accounts, creating an authorization bypass that can allow an attacker to link a SCIM token to another user's identity.
5
The FreeRDP Windows client (before 3.29.0) has a heap buffer overflow in the clipboard virtual channel when processing oversized CLIPRDR_FILE_CONTENTS_RESPONSE PDUs; a malicious RDP server can trigger arbitrary heap corruption, potentially enabling remote code execution on connecting clients.
6
ArcadeDB (before 26.7.2) permits JavaScript trigger scripts to access java.lang.* classes including Runtime.exec(), meaning any authenticated user with UPDATE_SCHEMA permission can achieve OS-level command execution on the database host.
7
FreeRDP clients (before 3.29.0) leak up to 1024 bytes of heap memory per WebSocket Pong reply when connected to a malicious gateway, as the response buffer is not trimmed to the actual Ping payload length — a significant information disclosure risk.
8
GitPython 3.1.50 fails to block the joined short-option form '-u<helper>' when enforcing its unsafe-option gate, allowing an attacker who can influence clone options to inject a malicious upload-pack helper and execute arbitrary commands on the host running the clone.
9
ArcadeDB (before 26.7.2) does not enforce scripting authorization on SQL DEFINE FUNCTION statements using JavaScript, enabling any database-level user to bypass admin-only scripting restrictions and run arbitrary JS code server-side.
10
FreeRDP (≤3.28.0) copies the server-controlled RDP TargetNetAddress into the HTTP proxy CONNECT request without filtering CRLF or control characters, exposing clients using HTTP proxies to HTTP header injection attacks from a malicious or compromised RDP server.
Ransomware today
The thegentlemen ransomware group recently claimed the Municipal Chamber of Serra and CRB group in Brazil, targeting government and professional services sectors. Global Secret Group hit SPDM (healthcare) and Sinop Energia (energy and utilities), also both Brazilian organizations. Over the past 30 days, lockbit5 remains the most active group with 23 recorded victims, all in Brazil, followed by Section9, incransom, Global Secret Group, qilin, and Deadlock — painting a persistently aggressive ransomware environment.
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actor identities are being tracked with updated profiles, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel, though no confirmed victims are yet attributed to these groups in the current period. Their monitoring remains relevant as new infrastructure or campaigns may surface.
Brazil focus
Brazil is facing concentrated ransomware pressure across multiple critical sectors in recent weeks. Confirmed victims include a municipal government chamber (Serra), a healthcare organization (SPDM), an energy utility (Sinop Energia), and a professional services firm (CRB group), claimed by thegentlemen and Global Secret Group. Section9 also listed several Brazilian targets in agriculture, financial services, and an undisclosed sector — reinforcing that Brazilian organizations across virtually every vertical remain high-priority ransomware targets.
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Teams running WordPress with Single Sign On For TNG or WooCommerce Social Login should update immediately and audit recent authentication logs for anomalous account access. Organizations using FreeRDP (all platforms), better-auth, ArcadeDB, or GitPython should apply the 3.29.0, 1.6.11, 26.7.2, and patched GitPython releases respectively before exposing these services to untrusted peers.
Even on quieter vulnerability days, the real risk lies in what is already silently exposed — validating your own attack surface against these newly published critical CVEs is the only way to know if today's disclosures are already a problem in your environment.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →