Daily briefing · August 4, 2026

Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in Focus

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 4, 2026 was a calm day by exploitation metrics — no vulnerabilities confirmed in active use, no ready-made exploit kits observed, and no VulnCheck early-warning signals. However, 41 critical CVEs were published in a single day, and the 10 highlighted entries span remote code execution, authentication bypass, and memory corruption across platforms ranging from Android and Snapdragon to SD-WAN infrastructure and WordPress plugins. Defenders should treat the absence of confirmed exploitation as a window of opportunity, not a reason for complacency.

Today’s brief
  • No active exploitation or weaponized exploits confirmed today — monitoring posture is appropriate
  • 10 critical CVEs published, including a perfect CVSS 10.0 RCE in ONE agent hosts
  • HPE EdgeConnect SD-WAN Orchestrator carries two critical auth-bypass flaws in its REST API
  • Brazil faces a concentrated ransomware wave: lockbit5, Orova, and krybit all claimed victims recently
41
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-64633CVSS 10affects ONE
A CVSS 10.0 flaw enabling remote unauthenticated code execution on ONE agent hosts — the highest possible severity rating and the most urgent entry of the day. Any internet-exposed ONE agent should be treated as a priority patch target.
2
CVE-2026-14175CVSS 9.8affects HUMANIST Digital Human Resources
An unrestricted file upload vulnerability in HUMANIST Digital Human Resources (versions 26.0 before 26.1) allows attackers to upload web shells directly to the server, granting full remote control with no prior authentication required.
3
CVE-2026-15721CVSS 9.8affects HUMANIST Digital Human Resources
A cleartext storage flaw in the same HUMANIST Digital Human Resources product (26.0 before 26.1) exposes sensitive data and enables SQL injection, compounding the risk already introduced by CVE-2026-14175 in the same software version.
4
CVE-2026-16618CVSS 9.8PoCaffects Improve SEO
A proof-of-concept exists for this WordPress Improve SEO plugin flaw (through 2.0.11): unauthenticated users can upload executable PHP files and achieve remote code execution because only content-type is validated, not file extension — a classic and easily exploitable misconfiguration.
5
CVE-2026-45538CVSS 9.8affects opensips
A stack buffer overflow in OpenSIPS versions 4.0.0 and prior triggers when sip_to_json() processes SIP headers longer than 255 bytes without bounds checking — directly exploitable via crafted SIP messages on any exposed SIP server running this function.
6
CVE-2026-0163CVSS 9.8affects Android
A use-after-free in Android's vpu_ioctl.c enables remote escalation of privilege with no user interaction required, making it particularly dangerous on any Android device or platform exposing VPU interfaces to untrusted inputs.
7
CVE-2026-24254CVSS 9.8affects Dynamo
An out-of-bounds write in NVIDIA Dynamo's multimodal serving topology on Linux could lead to code execution, privilege escalation, data tampering, and denial of service — high risk for AI inference infrastructure running Dynamo in multi-tenant or internet-adjacent environments.
8
CVE-2026-63456CVSS 9.8affects EdgeConnect SD-WAN Orchestrator
One of two critical REST API authentication bypass flaws in HPE Networking EdgeConnect SD-WAN Orchestrator — an unauthenticated remote attacker could view and modify sensitive network configuration data, a severe risk for organizations using this product as their SD-WAN control plane.
9
CVE-2026-63455CVSS 9.8affects EdgeConnect SD-WAN Orchestrator
The second critical REST API authentication bypass in HPE EdgeConnect SD-WAN Orchestrator, paired with CVE-2026-63456 — both should be patched together, as they share the same attack surface and impact, effectively doubling the exposure window until remediation.
10
CVE-2026-25289CVSS 9.6affects Snapdragon
A memory corruption vulnerability in Qualcomm Snapdragon triggered by malformed NAN Service Discovery Frames with invalid length values — affects a wide range of devices using Snapdragon chipsets and can be reached over Wi-Fi proximity, making it relevant for mobile and IoT fleets.
Ransomware today

Ransomware activity targeting Brazilian organizations has been significant in recent days. The groups krybit, Orova, and lockbit5 each claimed new Brazilian victims, hitting cesmac.edu.br (education), eSysTech (technology), and rai.com.br respectively. Over the past 30 days, lockbit5 stands out as the most active group with 24 confirmed victims, all in Brazil, underscoring a persistent and focused campaign against the country.

cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs

Several threat actor names have surfaced in recent tracking updates, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — none currently have confirmed victim counts, suggesting they may be newly observed, rebranding, or operating with limited public visibility. Their presence in threat intelligence feeds warrants monitoring, particularly coinbasecartel and apt73, whose naming conventions suggest targeted financial and state-sponsored motivations respectively.

Brazil focus

Brazil continues to be a primary ransomware target in the current cycle, with victims spanning education (cesmac.edu.br), technology (eSysTech), energy (Sinop Energia), healthcare (SPDM), government (The Municipal Chamber of Serra), and professional services (CRB group). Groups including thegentlemen, Global Secret Group, lockbit5, and krybit have all claimed Brazilian victims recently, reflecting a broad and cross-sector threat landscape. Organizations in these verticals should prioritize incident response readiness and verify the integrity of backups and remote access controls.

eSysTechOrova · Technology
cesmac.edu.brkrybit · Education
rai.com.brlockbit5 · Other
CRB groupthegentlemen · Professional Services
The Municipal Chamber of Serrathegentlemen · Government & Defense
Sinop EnergiaGlobal Secret Group · Energy & Utilities
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Prioritize patching CVE-2026-64633 (ONE, CVSS 10.0) and the two HPE EdgeConnect SD-WAN Orchestrator authentication bypass flaws (CVE-2026-63456 and CVE-2026-63455) as these expose critical infrastructure with no authentication barrier. For the WordPress and HUMANIST HR flaws, validate file upload controls and restrict direct web access to upload directories while patches are applied.
With no confirmed exploitation today but a high volume of new critical CVEs, now is the right moment to map your asset inventory against the affected products and validate whether your current controls would actually detect or block exploitation attempts before attackers catch up.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share