Daily briefing · August 3, 2026

Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 Vulnerabilities

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 3, 2026 brings a calm but technically dense day, with 238 new CVEs published and 45 rated critical — none yet confirmed as actively exploited. The standout story is a cluster of maximum-severity flaws in Adobe Campaign Classic, alongside a critical authentication bypass in WAPT Server and notable SQL injection chains in the SiYuan note-taking platform. No weaponized exploits or KEV additions were recorded, but the sheer concentration of CVSS 10.0 entries across a single product line warrants immediate attention from defenders.

Today’s brief
  • Adobe Campaign Classic receives five critical CVEs in one day, including three CVSS 10.0 flaws covering template injection, SSRF, and SQL injection — all exploitable without user interaction.
  • WAPT Server (pre-2.6.1.17813) exposes a remote, unauthenticated session-token hijacking flaw scored CVSS 10.0 — patch or isolate immediately.
  • SiYuan note-taking app carries three critical SQL injection flaws, one armed on the same day as disclosure, reachable by unauthenticated users when publish mode is enabled.
  • ChamaWP WordPress plugin allows unauthenticated password reset of any user, including admins — a full site takeover risk for affected WordPress deployments.
45
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-48323CVSS 10affects Adobe Campaign Classic
A template engine injection flaw in Adobe Campaign Classic allows arbitrary code execution in the current user's context with no user interaction required and a changed scope — any internet-exposed ACC instance should be treated as compromised until patched.
2
CVE-2026-48331CVSS 10affects Adobe Campaign Classic
An SSRF vulnerability in Adobe Campaign Classic can be leveraged for privilege escalation without user interaction, potentially allowing attackers to pivot to internal network resources or cloud metadata services.
3
CVE-2026-48330CVSS 10affects Adobe Campaign Classic
A SQL injection flaw in Adobe Campaign Classic enables arbitrary code execution and elevated database access with no user interaction; combined with other CVEs in this batch, the attack surface in ACC is exceptionally broad today.
4
CVE-2026-33591CVSS 10affects WAPT Server
WAPT Server before 2.6.1.17813 allows a remote unauthenticated attacker to retrieve a valid session token for any targeted account via a specially crafted packet — effectively a full authentication bypass with a perfect CVSS 10.0 score.
5
CVE-2026-48326CVSS 9.9affects Adobe Campaign Classic
A second SQL injection path in Adobe Campaign Classic, exploitable by a low-privileged attacker with scope change and no user interaction, making it a viable lateral movement vector inside enterprise environments running ACC.
6
CVE-2026-69085CVSS 9.9affects siyuan
SiYuan's /api/filetree/searchDocs endpoint passes user input directly into SQL with no sanitization, reachable by RoleReader tokens or anonymously when publish authentication is disabled — data exfiltration and manipulation are realistic outcomes.
7
CVE-2026-69084CVSS 9.9affects siyuan
SiYuan's /api/search/searchEmbedBlock endpoint exposes a read-write database handle to client-supplied SQL with no restrictions beyond a basic auth check, meaning publish RoleReader tokens or anonymous users can issue destructive queries against the main database.
8
CVE-2026-69083CVSS 9.9PoCsame dayaffects siyuan
This SiYuan SQL injection was armed with a proof-of-concept on the same day it was disclosed, targeting the fullTextSearchAssetContent endpoint with no authentication required — the zero-day weaponization speed makes this the highest-urgency SiYuan entry in today's batch.
9
CVE-2026-16300CVSS 9.8PoCaffects ChamaWP
ChamaWP for WordPress before 1.0.13 fails to properly validate password reset requests, letting unauthenticated attackers reset passwords for any account including administrators — a straightforward path to full site takeover with a published proof-of-concept.
10
CVE-2026-48333CVSS 9.8affects Adobe Campaign Classic
An incorrect authorization flaw in Adobe Campaign Classic enables privilege escalation without user interaction, rounding out a day where ACC effectively presents attackers with a multi-vector exploitation menu spanning injection, SSRF, and authorization failures.
Ransomware today

Ransomware activity against Brazilian targets remains intense: lockbit5 recently claimed rai.com.br, while thegentlemen listed The Municipal Chamber of Serra and CRB group among its victims. Over the past 30 days, lockbit5 leads all groups with 24 claimed victims, all in Brazil, underscoring a sustained focus on Brazilian organizations across multiple sectors.

rai.com.br BRlockbit5 · Other
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs

Several threat actors have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. No specific victims are currently attributed to these groups in the available data, but their presence in threat intelligence feeds suggests ongoing reconnaissance or operational preparation.

Brazil focus

Brazil continues to face disproportionate ransomware pressure, with recent victims spanning government (The Municipal Chamber of Serra), healthcare (SPDM), energy (Sinop Energia), financial services, agriculture, and professional services. Groups including lockbit5, Section9, Global Secret Group, and thegentlemen have all claimed Brazilian organizations in the past 30 days, painting a broad-sector targeting picture that defenders across industries should take seriously.

rai.com.brlockbit5 · Other
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Today’s recommendation: Prioritize emergency patching of Adobe Campaign Classic across all five CVEs published today, isolate or update WAPT Server to 2.6.1.17813 or later, and disable unauthenticated publish mode in SiYuan deployments pending a patch to the three SQL injection endpoints.
Even on a day without confirmed active exploitation, the density of critical zero-interaction flaws published makes it essential to validate which of these products are present in your environment and assess your actual exposure before threat actors move first.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share