Daily briefing · August 4, 2026
Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in Focus
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 4, 2026 was a calm day by exploitation metrics — no vulnerabilities confirmed in active use, no ready-made exploit kits observed, and no VulnCheck early-warning signals. However, 41 critical CVEs were published in a single day, and the 10 highlighted entries span remote code execution, authentication bypass, and memory corruption across platforms ranging from Android and Snapdragon to SD-WAN infrastructure and WordPress plugins. Defenders should treat the absence of confirmed exploitation as a window of opportunity, not a reason for complacency.
Today’s brief
- No active exploitation or weaponized exploits confirmed today — monitoring posture is appropriate
- 10 critical CVEs published, including a perfect CVSS 10.0 RCE in ONE agent hosts
- HPE EdgeConnect SD-WAN Orchestrator carries two critical auth-bypass flaws in its REST API
- Brazil faces a concentrated ransomware wave: lockbit5, Orova, and krybit all claimed victims recently
Critical highlights
1
A CVSS 10.0 flaw enabling remote unauthenticated code execution on ONE agent hosts — the highest possible severity rating and the most urgent entry of the day. Any internet-exposed ONE agent should be treated as a priority patch target.
2
An unrestricted file upload vulnerability in HUMANIST Digital Human Resources (versions 26.0 before 26.1) allows attackers to upload web shells directly to the server, granting full remote control with no prior authentication required.
3
A cleartext storage flaw in the same HUMANIST Digital Human Resources product (26.0 before 26.1) exposes sensitive data and enables SQL injection, compounding the risk already introduced by CVE-2026-14175 in the same software version.
4
A proof-of-concept exists for this WordPress Improve SEO plugin flaw (through 2.0.11): unauthenticated users can upload executable PHP files and achieve remote code execution because only content-type is validated, not file extension — a classic and easily exploitable misconfiguration.
5
A stack buffer overflow in OpenSIPS versions 4.0.0 and prior triggers when sip_to_json() processes SIP headers longer than 255 bytes without bounds checking — directly exploitable via crafted SIP messages on any exposed SIP server running this function.
6
A use-after-free in Android's vpu_ioctl.c enables remote escalation of privilege with no user interaction required, making it particularly dangerous on any Android device or platform exposing VPU interfaces to untrusted inputs.
7
An out-of-bounds write in NVIDIA Dynamo's multimodal serving topology on Linux could lead to code execution, privilege escalation, data tampering, and denial of service — high risk for AI inference infrastructure running Dynamo in multi-tenant or internet-adjacent environments.
8
One of two critical REST API authentication bypass flaws in HPE Networking EdgeConnect SD-WAN Orchestrator — an unauthenticated remote attacker could view and modify sensitive network configuration data, a severe risk for organizations using this product as their SD-WAN control plane.
9
The second critical REST API authentication bypass in HPE EdgeConnect SD-WAN Orchestrator, paired with CVE-2026-63456 — both should be patched together, as they share the same attack surface and impact, effectively doubling the exposure window until remediation.
10
A memory corruption vulnerability in Qualcomm Snapdragon triggered by malformed NAN Service Discovery Frames with invalid length values — affects a wide range of devices using Snapdragon chipsets and can be reached over Wi-Fi proximity, making it relevant for mobile and IoT fleets.
Ransomware today
Ransomware activity targeting Brazilian organizations has been significant in recent days. The groups krybit, Orova, and lockbit5 each claimed new Brazilian victims, hitting cesmac.edu.br (education), eSysTech (technology), and rai.com.br respectively. Over the past 30 days, lockbit5 stands out as the most active group with 24 confirmed victims, all in Brazil, underscoring a persistent and focused campaign against the country.
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs
Several threat actor names have surfaced in recent tracking updates, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — none currently have confirmed victim counts, suggesting they may be newly observed, rebranding, or operating with limited public visibility. Their presence in threat intelligence feeds warrants monitoring, particularly coinbasecartel and apt73, whose naming conventions suggest targeted financial and state-sponsored motivations respectively.
Brazil focus
Brazil continues to be a primary ransomware target in the current cycle, with victims spanning education (cesmac.edu.br), technology (eSysTech), energy (Sinop Energia), healthcare (SPDM), government (The Municipal Chamber of Serra), and professional services (CRB group). Groups including thegentlemen, Global Secret Group, lockbit5, and krybit have all claimed Brazilian victims recently, reflecting a broad and cross-sector threat landscape. Organizations in these verticals should prioritize incident response readiness and verify the integrity of backups and remote access controls.
eSysTechOrova · Technology
cesmac.edu.brkrybit · Education
rai.com.brlockbit5 · Other
CRB groupthegentlemen · Professional Services
The Municipal Chamber of Serrathegentlemen · Government & Defense
Sinop EnergiaGlobal Secret Group · Energy & Utilities
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Prioritize patching CVE-2026-64633 (ONE, CVSS 10.0) and the two HPE EdgeConnect SD-WAN Orchestrator authentication bypass flaws (CVE-2026-63456 and CVE-2026-63455) as these expose critical infrastructure with no authentication barrier. For the WordPress and HUMANIST HR flaws, validate file upload controls and restrict direct web access to upload directories while patches are applied.
With no confirmed exploitation today but a high volume of new critical CVEs, now is the right moment to map your asset inventory against the affected products and validate whether your current controls would actually detect or block exploitation attempts before attackers catch up.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →