Daily briefing · August 1, 2026
WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 1, 2026 brought a calm vulnerability landscape with no active exploitation or weaponized exploits confirmed, yet 15 critical-severity CVEs were published, demanding prompt attention from defenders. Leading the pack are two WordPress authentication bypass flaws and a cluster of critical FreeRDP and better-auth issues that could expose broad enterprise surfaces. While the threat level is measured, the density of authentication and memory-corruption vulnerabilities in widely deployed software warrants focused patching this week.
Today’s brief
- No CVEs in active exploitation (KEV) today, but 15 critical-severity vulnerabilities were published — patching remains urgent
- Two WordPress plugin auth bypasses (Single Sign On For TNG and WooCommerce Social Login) allow unauthenticated account takeover
- FreeRDP received three critical CVEs affecting heap integrity, WebSocket disclosure, and HTTP proxy header injection
- Brazil is actively targeted by ransomware: thegentlemen and Global Secret Group hit government, healthcare, and energy sectors recently
Critical highlights
1
A CVSS 9.8 unauthenticated password reset flaw in the Single Sign On For TNG WordPress plugin (≤2.0.0) allows any attacker to take over accounts without credentials — notably, a proof-of-concept was published the same day as disclosure, making rapid exploitation highly plausible.
2
The WooCommerce Social Login plugin (≤2.8.7) accepts Apple id_tokens without verifying JWT signatures, issuers, audiences, or expiry, effectively allowing anyone to forge an Apple identity and bypass authentication on WooCommerce stores.
3
better-auth (before 1.6.11) advertises the 'none' JWT algorithm and accepts plain PKCE by default in its OIDC and MCP plugins, enabling attackers to submit unsigned tokens or intercept authorization codes through algorithm negotiation abuse.
4
The @better-auth/scim plugin fails to prevent SCIM token issuance for provider IDs already held by existing SSO, SAML, or OAuth accounts, creating an authorization bypass that can allow an attacker to link a SCIM token to another user's identity.
5
The FreeRDP Windows client (before 3.29.0) has a heap buffer overflow in the clipboard virtual channel when processing oversized CLIPRDR_FILE_CONTENTS_RESPONSE PDUs; a malicious RDP server can trigger arbitrary heap corruption, potentially enabling remote code execution on connecting clients.
6
ArcadeDB (before 26.7.2) permits JavaScript trigger scripts to access java.lang.* classes including Runtime.exec(), meaning any authenticated user with UPDATE_SCHEMA permission can achieve OS-level command execution on the database host.
7
FreeRDP clients (before 3.29.0) leak up to 1024 bytes of heap memory per WebSocket Pong reply when connected to a malicious gateway, as the response buffer is not trimmed to the actual Ping payload length — a significant information disclosure risk.
8
GitPython 3.1.50 fails to block the joined short-option form '-u<helper>' when enforcing its unsafe-option gate, allowing an attacker who can influence clone options to inject a malicious upload-pack helper and execute arbitrary commands on the host running the clone.
9
ArcadeDB (before 26.7.2) does not enforce scripting authorization on SQL DEFINE FUNCTION statements using JavaScript, enabling any database-level user to bypass admin-only scripting restrictions and run arbitrary JS code server-side.
10
FreeRDP (≤3.28.0) copies the server-controlled RDP TargetNetAddress into the HTTP proxy CONNECT request without filtering CRLF or control characters, exposing clients using HTTP proxies to HTTP header injection attacks from a malicious or compromised RDP server.
Ransomware today
The thegentlemen ransomware group recently claimed the Municipal Chamber of Serra and CRB group in Brazil, targeting government and professional services sectors. Global Secret Group hit SPDM (healthcare) and Sinop Energia (energy and utilities), also both Brazilian organizations. Over the past 30 days, lockbit5 remains the most active group with 23 recorded victims, all in Brazil, followed by Section9, incransom, Global Secret Group, qilin, and Deadlock — painting a persistently aggressive ransomware environment.
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
SPDM BRGlobal Secret Group · Healthcare
Sinop Energia BRGlobal Secret Group · Energy & Utilities
lockbit5 23Section9 6incransom 4Global Secret Group 4qilin 3Deadlock 3
Active groups & APTs
Several threat actor identities are being tracked with updated profiles, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel, though no confirmed victims are yet attributed to these groups in the current period. Their monitoring remains relevant as new infrastructure or campaigns may surface.
Brazil focus
Brazil is facing concentrated ransomware pressure across multiple critical sectors in recent weeks. Confirmed victims include a municipal government chamber (Serra), a healthcare organization (SPDM), an energy utility (Sinop Energia), and a professional services firm (CRB group), claimed by thegentlemen and Global Secret Group. Section9 also listed several Brazilian targets in agriculture, financial services, and an undisclosed sector — reinforcing that Brazilian organizations across virtually every vertical remain high-priority ransomware targets.
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Teams running WordPress with Single Sign On For TNG or WooCommerce Social Login should update immediately and audit recent authentication logs for anomalous account access. Organizations using FreeRDP (all platforms), better-auth, ArcadeDB, or GitPython should apply the 3.29.0, 1.6.11, 26.7.2, and patched GitPython releases respectively before exposing these services to untrusted peers.
Even on quieter vulnerability days, the real risk lies in what is already silently exposed — validating your own attack surface against these newly published critical CVEs is the only way to know if today's disclosures are already a problem in your environment.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →