Daily briefing · August 1, 2026

WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 1, 2026 brought a calm vulnerability landscape with no active exploitation or weaponized exploits confirmed, yet 15 critical-severity CVEs were published, demanding prompt attention from defenders. Leading the pack are two WordPress authentication bypass flaws and a cluster of critical FreeRDP and better-auth issues that could expose broad enterprise surfaces. While the threat level is measured, the density of authentication and memory-corruption vulnerabilities in widely deployed software warrants focused patching this week.

Today’s brief
  • No CVEs in active exploitation (KEV) today, but 15 critical-severity vulnerabilities were published — patching remains urgent
  • Two WordPress plugin auth bypasses (Single Sign On For TNG and WooCommerce Social Login) allow unauthenticated account takeover
  • FreeRDP received three critical CVEs affecting heap integrity, WebSocket disclosure, and HTTP proxy header injection
  • Brazil is actively targeted by ransomware: thegentlemen and Global Secret Group hit government, healthcare, and energy sectors recently
15
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-15964CVSS 9.8PoCsame dayaffects Single Sign On For TNG
A CVSS 9.8 unauthenticated password reset flaw in the Single Sign On For TNG WordPress plugin (≤2.0.0) allows any attacker to take over accounts without credentials — notably, a proof-of-concept was published the same day as disclosure, making rapid exploitation highly plausible.
2
CVE-2026-8457CVSS 9.8affects WooCommerce - Social Login
The WooCommerce Social Login plugin (≤2.8.7) accepts Apple id_tokens without verifying JWT signatures, issuers, audiences, or expiry, effectively allowing anyone to forge an Apple identity and bypass authentication on WooCommerce stores.
3
CVE-2026-67336CVSS 9.4affects better-auth
better-auth (before 1.6.11) advertises the 'none' JWT algorithm and accepts plain PKCE by default in its OIDC and MCP plugins, enabling attackers to submit unsigned tokens or intercept authorization codes through algorithm negotiation abuse.
4
CVE-2026-67330CVSS 9.4affects scim
The @better-auth/scim plugin fails to prevent SCIM token issuance for provider IDs already held by existing SSO, SAML, or OAuth accounts, creating an authorization bypass that can allow an attacker to link a SCIM token to another user's identity.
5
CVE-2026-67305CVSS 9.4affects FreeRDP
The FreeRDP Windows client (before 3.29.0) has a heap buffer overflow in the clipboard virtual channel when processing oversized CLIPRDR_FILE_CONTENTS_RESPONSE PDUs; a malicious RDP server can trigger arbitrary heap corruption, potentially enabling remote code execution on connecting clients.
6
CVE-2026-67340CVSS 9.3affects arcadedb
ArcadeDB (before 26.7.2) permits JavaScript trigger scripts to access java.lang.* classes including Runtime.exec(), meaning any authenticated user with UPDATE_SCHEMA permission can achieve OS-level command execution on the database host.
7
CVE-2026-67292CVSS 9.3affects FreeRDP
FreeRDP clients (before 3.29.0) leak up to 1024 bytes of heap memory per WebSocket Pong reply when connected to a malicious gateway, as the response buffer is not trimmed to the actual Ping payload length — a significant information disclosure risk.
8
CVE-2026-67324CVSS 9.3affects GitPython
GitPython 3.1.50 fails to block the joined short-option form '-u<helper>' when enforcing its unsafe-option gate, allowing an attacker who can influence clone options to inject a malicious upload-pack helper and execute arbitrary commands on the host running the clone.
9
CVE-2026-67341CVSS 9.3affects arcadedb
ArcadeDB (before 26.7.2) does not enforce scripting authorization on SQL DEFINE FUNCTION statements using JavaScript, enabling any database-level user to bypass admin-only scripting restrictions and run arbitrary JS code server-side.
10
CVE-2026-67289CVSS 9.3affects FreeRDP
FreeRDP (≤3.28.0) copies the server-controlled RDP TargetNetAddress into the HTTP proxy CONNECT request without filtering CRLF or control characters, exposing clients using HTTP proxies to HTTP header injection attacks from a malicious or compromised RDP server.
Ransomware today

The thegentlemen ransomware group recently claimed the Municipal Chamber of Serra and CRB group in Brazil, targeting government and professional services sectors. Global Secret Group hit SPDM (healthcare) and Sinop Energia (energy and utilities), also both Brazilian organizations. Over the past 30 days, lockbit5 remains the most active group with 23 recorded victims, all in Brazil, followed by Section9, incransom, Global Secret Group, qilin, and Deadlock — painting a persistently aggressive ransomware environment.

The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs

Several threat actor identities are being tracked with updated profiles, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel, though no confirmed victims are yet attributed to these groups in the current period. Their monitoring remains relevant as new infrastructure or campaigns may surface.

Brazil focus

Brazil is facing concentrated ransomware pressure across multiple critical sectors in recent weeks. Confirmed victims include a municipal government chamber (Serra), a healthcare organization (SPDM), an energy utility (Sinop Energia), and a professional services firm (CRB group), claimed by thegentlemen and Global Secret Group. Section9 also listed several Brazilian targets in agriculture, financial services, and an undisclosed sector — reinforcing that Brazilian organizations across virtually every vertical remain high-priority ransomware targets.

The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Teams running WordPress with Single Sign On For TNG or WooCommerce Social Login should update immediately and audit recent authentication logs for anomalous account access. Organizations using FreeRDP (all platforms), better-auth, ArcadeDB, or GitPython should apply the 3.29.0, 1.6.11, 26.7.2, and patched GitPython releases respectively before exposing these services to untrusted peers.
Even on quieter vulnerability days, the real risk lies in what is already silently exposed — validating your own attack surface against these newly published critical CVEs is the only way to know if today's disclosures are already a problem in your environment.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share