Daily briefing · August 3, 2026

Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 Vulnerabilities

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 3, 2026 brings a calm but technically dense day, with 238 new CVEs published and 45 rated critical — none yet confirmed as actively exploited. The standout story is a cluster of maximum-severity flaws in Adobe Campaign Classic, alongside a critical authentication bypass in WAPT Server and notable SQL injection chains in the SiYuan note-taking platform. No weaponized exploits or KEV additions were recorded, but the sheer concentration of CVSS 10.0 entries across a single product line warrants immediate attention from defenders.

Today’s brief
  • Adobe Campaign Classic receives five critical CVEs in one day, including three CVSS 10.0 flaws covering template injection, SSRF, and SQL injection — all exploitable without user interaction.
  • WAPT Server (pre-2.6.1.17813) exposes a remote, unauthenticated session-token hijacking flaw scored CVSS 10.0 — patch or isolate immediately.
  • SiYuan note-taking app carries three critical SQL injection flaws, one armed on the same day as disclosure, reachable by unauthenticated users when publish mode is enabled.
  • ChamaWP WordPress plugin allows unauthenticated password reset of any user, including admins — a full site takeover risk for affected WordPress deployments.
45
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-48323CVSS 10affects Adobe Campaign Classic
A template engine injection flaw in Adobe Campaign Classic allows arbitrary code execution in the current user's context with no user interaction required and a changed scope — any internet-exposed ACC instance should be treated as compromised until patched.
2
CVE-2026-48331CVSS 10affects Adobe Campaign Classic
An SSRF vulnerability in Adobe Campaign Classic can be leveraged for privilege escalation without user interaction, potentially allowing attackers to pivot to internal network resources or cloud metadata services.
3
CVE-2026-48330CVSS 10affects Adobe Campaign Classic
A SQL injection flaw in Adobe Campaign Classic enables arbitrary code execution and elevated database access with no user interaction; combined with other CVEs in this batch, the attack surface in ACC is exceptionally broad today.
4
CVE-2026-33591CVSS 10affects WAPT Server
WAPT Server before 2.6.1.17813 allows a remote unauthenticated attacker to retrieve a valid session token for any targeted account via a specially crafted packet — effectively a full authentication bypass with a perfect CVSS 10.0 score.
5
CVE-2026-48326CVSS 9.9affects Adobe Campaign Classic
A second SQL injection path in Adobe Campaign Classic, exploitable by a low-privileged attacker with scope change and no user interaction, making it a viable lateral movement vector inside enterprise environments running ACC.
6
CVE-2026-69085CVSS 9.9affects siyuan
SiYuan's /api/filetree/searchDocs endpoint passes user input directly into SQL with no sanitization, reachable by RoleReader tokens or anonymously when publish authentication is disabled — data exfiltration and manipulation are realistic outcomes.
7
CVE-2026-69084CVSS 9.9affects siyuan
SiYuan's /api/search/searchEmbedBlock endpoint exposes a read-write database handle to client-supplied SQL with no restrictions beyond a basic auth check, meaning publish RoleReader tokens or anonymous users can issue destructive queries against the main database.
8
CVE-2026-69083CVSS 9.9PoCsame dayaffects siyuan
This SiYuan SQL injection was armed with a proof-of-concept on the same day it was disclosed, targeting the fullTextSearchAssetContent endpoint with no authentication required — the zero-day weaponization speed makes this the highest-urgency SiYuan entry in today's batch.
9
CVE-2026-16300CVSS 9.8PoCaffects ChamaWP
ChamaWP for WordPress before 1.0.13 fails to properly validate password reset requests, letting unauthenticated attackers reset passwords for any account including administrators — a straightforward path to full site takeover with a published proof-of-concept.
10
CVE-2026-48333CVSS 9.8affects Adobe Campaign Classic
An incorrect authorization flaw in Adobe Campaign Classic enables privilege escalation without user interaction, rounding out a day where ACC effectively presents attackers with a multi-vector exploitation menu spanning injection, SSRF, and authorization failures.
Ransomware today

Ransomware activity against Brazilian targets remains intense: lockbit5 recently claimed rai.com.br, while thegentlemen listed The Municipal Chamber of Serra and CRB group among its victims. Over the past 30 days, lockbit5 leads all groups with 24 claimed victims, all in Brazil, underscoring a sustained focus on Brazilian organizations across multiple sectors.

rai.com.br BRlockbit5 · Other
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs

Several threat actors have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. No specific victims are currently attributed to these groups in the available data, but their presence in threat intelligence feeds suggests ongoing reconnaissance or operational preparation.

Brazil focus

Brazil continues to face disproportionate ransomware pressure, with recent victims spanning government (The Municipal Chamber of Serra), healthcare (SPDM), energy (Sinop Energia), financial services, agriculture, and professional services. Groups including lockbit5, Section9, Global Secret Group, and thegentlemen have all claimed Brazilian organizations in the past 30 days, painting a broad-sector targeting picture that defenders across industries should take seriously.

rai.com.brlockbit5 · Other
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Today’s recommendation: Prioritize emergency patching of Adobe Campaign Classic across all five CVEs published today, isolate or update WAPT Server to 2.6.1.17813 or later, and disable unauthenticated publish mode in SiYuan deployments pending a patch to the three SQL injection endpoints.
Even on a day without confirmed active exploitation, the density of critical zero-interaction flaws published makes it essential to validate which of these products are present in your environment and assess your actual exposure before threat actors move first.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →