Daily briefing · August 3, 2026
Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 Vulnerabilities
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 3, 2026 brings a calm but technically dense day, with 238 new CVEs published and 45 rated critical — none yet confirmed as actively exploited. The standout story is a cluster of maximum-severity flaws in Adobe Campaign Classic, alongside a critical authentication bypass in WAPT Server and notable SQL injection chains in the SiYuan note-taking platform. No weaponized exploits or KEV additions were recorded, but the sheer concentration of CVSS 10.0 entries across a single product line warrants immediate attention from defenders.
Today’s brief
- Adobe Campaign Classic receives five critical CVEs in one day, including three CVSS 10.0 flaws covering template injection, SSRF, and SQL injection — all exploitable without user interaction.
- WAPT Server (pre-2.6.1.17813) exposes a remote, unauthenticated session-token hijacking flaw scored CVSS 10.0 — patch or isolate immediately.
- SiYuan note-taking app carries three critical SQL injection flaws, one armed on the same day as disclosure, reachable by unauthenticated users when publish mode is enabled.
- ChamaWP WordPress plugin allows unauthenticated password reset of any user, including admins — a full site takeover risk for affected WordPress deployments.
Critical highlights
1
A template engine injection flaw in Adobe Campaign Classic allows arbitrary code execution in the current user's context with no user interaction required and a changed scope — any internet-exposed ACC instance should be treated as compromised until patched.
2
An SSRF vulnerability in Adobe Campaign Classic can be leveraged for privilege escalation without user interaction, potentially allowing attackers to pivot to internal network resources or cloud metadata services.
3
A SQL injection flaw in Adobe Campaign Classic enables arbitrary code execution and elevated database access with no user interaction; combined with other CVEs in this batch, the attack surface in ACC is exceptionally broad today.
4
WAPT Server before 2.6.1.17813 allows a remote unauthenticated attacker to retrieve a valid session token for any targeted account via a specially crafted packet — effectively a full authentication bypass with a perfect CVSS 10.0 score.
5
A second SQL injection path in Adobe Campaign Classic, exploitable by a low-privileged attacker with scope change and no user interaction, making it a viable lateral movement vector inside enterprise environments running ACC.
6
SiYuan's /api/filetree/searchDocs endpoint passes user input directly into SQL with no sanitization, reachable by RoleReader tokens or anonymously when publish authentication is disabled — data exfiltration and manipulation are realistic outcomes.
7
SiYuan's /api/search/searchEmbedBlock endpoint exposes a read-write database handle to client-supplied SQL with no restrictions beyond a basic auth check, meaning publish RoleReader tokens or anonymous users can issue destructive queries against the main database.
8
This SiYuan SQL injection was armed with a proof-of-concept on the same day it was disclosed, targeting the fullTextSearchAssetContent endpoint with no authentication required — the zero-day weaponization speed makes this the highest-urgency SiYuan entry in today's batch.
9
ChamaWP for WordPress before 1.0.13 fails to properly validate password reset requests, letting unauthenticated attackers reset passwords for any account including administrators — a straightforward path to full site takeover with a published proof-of-concept.
10
An incorrect authorization flaw in Adobe Campaign Classic enables privilege escalation without user interaction, rounding out a day where ACC effectively presents attackers with a multi-vector exploitation menu spanning injection, SSRF, and authorization failures.
Ransomware today
Ransomware activity against Brazilian targets remains intense: lockbit5 recently claimed rai.com.br, while thegentlemen listed The Municipal Chamber of Serra and CRB group among its victims. Over the past 30 days, lockbit5 leads all groups with 24 claimed victims, all in Brazil, underscoring a sustained focus on Brazilian organizations across multiple sectors.
rai.com.br BRlockbit5 · Other
The Municipal Chamber of Serra BRthegentlemen · Government & Defense
CRB group BRthegentlemen · Professional Services
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs
Several threat actors have been flagged as active or updated in recent tracking, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. No specific victims are currently attributed to these groups in the available data, but their presence in threat intelligence feeds suggests ongoing reconnaissance or operational preparation.
Brazil focus
Brazil continues to face disproportionate ransomware pressure, with recent victims spanning government (The Municipal Chamber of Serra), healthcare (SPDM), energy (Sinop Energia), financial services, agriculture, and professional services. Groups including lockbit5, Section9, Global Secret Group, and thegentlemen have all claimed Brazilian organizations in the past 30 days, painting a broad-sector targeting picture that defenders across industries should take seriously.
rai.com.brlockbit5 · Other
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
*****.ind.brSection9 · Agriculture and Food Production
*****.com.brSection9 · Financial Services
********.com.brSection9
Today’s recommendation: Prioritize emergency patching of Adobe Campaign Classic across all five CVEs published today, isolate or update WAPT Server to 2.6.1.17813 or later, and disable unauthenticated publish mode in SiYuan deployments pending a patch to the three SQL injection endpoints.
Even on a day without confirmed active exploitation, the density of critical zero-interaction flaws published makes it essential to validate which of these products are present in your environment and assess your actual exposure before threat actors move first.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →