Daily briefing · August 4, 2026

Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in Focus

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 4, 2026 was a calm day by exploitation metrics — no vulnerabilities confirmed in active use, no ready-made exploit kits observed, and no VulnCheck early-warning signals. However, 41 critical CVEs were published in a single day, and the 10 highlighted entries span remote code execution, authentication bypass, and memory corruption across platforms ranging from Android and Snapdragon to SD-WAN infrastructure and WordPress plugins. Defenders should treat the absence of confirmed exploitation as a window of opportunity, not a reason for complacency.

Today’s brief
  • No active exploitation or weaponized exploits confirmed today — monitoring posture is appropriate
  • 10 critical CVEs published, including a perfect CVSS 10.0 RCE in ONE agent hosts
  • HPE EdgeConnect SD-WAN Orchestrator carries two critical auth-bypass flaws in its REST API
  • Brazil faces a concentrated ransomware wave: lockbit5, Orova, and krybit all claimed victims recently
41
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-64633CVSS 10affects ONE
A CVSS 10.0 flaw enabling remote unauthenticated code execution on ONE agent hosts — the highest possible severity rating and the most urgent entry of the day. Any internet-exposed ONE agent should be treated as a priority patch target.
2
CVE-2026-14175CVSS 9.8affects HUMANIST Digital Human Resources
An unrestricted file upload vulnerability in HUMANIST Digital Human Resources (versions 26.0 before 26.1) allows attackers to upload web shells directly to the server, granting full remote control with no prior authentication required.
3
CVE-2026-15721CVSS 9.8affects HUMANIST Digital Human Resources
A cleartext storage flaw in the same HUMANIST Digital Human Resources product (26.0 before 26.1) exposes sensitive data and enables SQL injection, compounding the risk already introduced by CVE-2026-14175 in the same software version.
4
CVE-2026-16618CVSS 9.8PoCaffects Improve SEO
A proof-of-concept exists for this WordPress Improve SEO plugin flaw (through 2.0.11): unauthenticated users can upload executable PHP files and achieve remote code execution because only content-type is validated, not file extension — a classic and easily exploitable misconfiguration.
5
CVE-2026-45538CVSS 9.8affects opensips
A stack buffer overflow in OpenSIPS versions 4.0.0 and prior triggers when sip_to_json() processes SIP headers longer than 255 bytes without bounds checking — directly exploitable via crafted SIP messages on any exposed SIP server running this function.
6
CVE-2026-0163CVSS 9.8affects Android
A use-after-free in Android's vpu_ioctl.c enables remote escalation of privilege with no user interaction required, making it particularly dangerous on any Android device or platform exposing VPU interfaces to untrusted inputs.
7
CVE-2026-24254CVSS 9.8affects Dynamo
An out-of-bounds write in NVIDIA Dynamo's multimodal serving topology on Linux could lead to code execution, privilege escalation, data tampering, and denial of service — high risk for AI inference infrastructure running Dynamo in multi-tenant or internet-adjacent environments.
8
CVE-2026-63456CVSS 9.8affects EdgeConnect SD-WAN Orchestrator
One of two critical REST API authentication bypass flaws in HPE Networking EdgeConnect SD-WAN Orchestrator — an unauthenticated remote attacker could view and modify sensitive network configuration data, a severe risk for organizations using this product as their SD-WAN control plane.
9
CVE-2026-63455CVSS 9.8affects EdgeConnect SD-WAN Orchestrator
The second critical REST API authentication bypass in HPE EdgeConnect SD-WAN Orchestrator, paired with CVE-2026-63456 — both should be patched together, as they share the same attack surface and impact, effectively doubling the exposure window until remediation.
10
CVE-2026-25289CVSS 9.6affects Snapdragon
A memory corruption vulnerability in Qualcomm Snapdragon triggered by malformed NAN Service Discovery Frames with invalid length values — affects a wide range of devices using Snapdragon chipsets and can be reached over Wi-Fi proximity, making it relevant for mobile and IoT fleets.
Ransomware today

Ransomware activity targeting Brazilian organizations has been significant in recent days. The groups krybit, Orova, and lockbit5 each claimed new Brazilian victims, hitting cesmac.edu.br (education), eSysTech (technology), and rai.com.br respectively. Over the past 30 days, lockbit5 stands out as the most active group with 24 confirmed victims, all in Brazil, underscoring a persistent and focused campaign against the country.

cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs

Several threat actor names have surfaced in recent tracking updates, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — none currently have confirmed victim counts, suggesting they may be newly observed, rebranding, or operating with limited public visibility. Their presence in threat intelligence feeds warrants monitoring, particularly coinbasecartel and apt73, whose naming conventions suggest targeted financial and state-sponsored motivations respectively.

Brazil focus

Brazil continues to be a primary ransomware target in the current cycle, with victims spanning education (cesmac.edu.br), technology (eSysTech), energy (Sinop Energia), healthcare (SPDM), government (The Municipal Chamber of Serra), and professional services (CRB group). Groups including thegentlemen, Global Secret Group, lockbit5, and krybit have all claimed Brazilian victims recently, reflecting a broad and cross-sector threat landscape. Organizations in these verticals should prioritize incident response readiness and verify the integrity of backups and remote access controls.

eSysTechOrova · Technology
cesmac.edu.brkrybit · Education
rai.com.brlockbit5 · Other
CRB groupthegentlemen · Professional Services
The Municipal Chamber of Serrathegentlemen · Government & Defense
Sinop EnergiaGlobal Secret Group · Energy & Utilities
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Prioritize patching CVE-2026-64633 (ONE, CVSS 10.0) and the two HPE EdgeConnect SD-WAN Orchestrator authentication bypass flaws (CVE-2026-63456 and CVE-2026-63455) as these expose critical infrastructure with no authentication barrier. For the WordPress and HUMANIST HR flaws, validate file upload controls and restrict direct web access to upload directories while patches are applied.
With no confirmed exploitation today but a high volume of new critical CVEs, now is the right moment to map your asset inventory against the affected products and validate whether your current controls would actually detect or block exploitation attempts before attackers catch up.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →