Daily briefing · August 5, 2026
Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 5, 2026 brought 400 new CVEs — 45 of them critical — yet no active exploitation or weaponized proof-of-concept code was confirmed for any of them, keeping the overall threat level calm. The day's highlights center on three high-impact product families: Cisco Catalyst SD-WAN Controller, Progress MarkLogic Server, and a cluster of critical flaws in tools ranging from OpenPLC Runtime to AI-agent framework PraisonAI. While no weaponized exploits are in circulation today, the severity scores and attack vectors demand immediate patching attention before that changes.
Today’s brief
- 45 critical CVEs published today — none yet confirmed in active exploitation or with a ready-made exploit module
- Cisco Catalyst SD-WAN Controller carries two CVSS 9.9 flaws (improper input validation and access control) requiring urgent patching in SD-WAN deployments
- Progress MarkLogic Server has three separate CVSS 9.9 privilege escalation paths — Hadoop, REST API patch, and SQL/SPARQL interfaces — all fixed in versions 11.3.6 and 12.0.3
- Brazil is under sustained ransomware pressure: four new victims confirmed recently, with lockbit5 leading the 30-day ranking
Critical highlights
1
A command injection vulnerability in PraisonAI's bundled Claude GitHub Actions workflow allows an attacker to inject arbitrary shell commands via a crafted pull request branch name, since the value is embedded in a Bash block without quoting or validation; any commenter can trigger the job, making this a serious supply-chain risk for teams using PraisonAI in CI/CD pipelines.
2
CVE-2026-10090CVSS 9.9affects Red Hat Advanced Cluster Management for Kubernetes 2 A CVSS 9.9 flaw in Red Hat ACM's Application Subscription controller lets a user with only namespace-scoped edit privileges create a malicious Helm Channel and Subscription, causing the app-subscription controller to fetch and apply attacker-controlled Helm charts — effectively granting cluster-level impact from minimal permissions.
3
Cisco's own internal security review uncovered improper input validation vulnerabilities in the Catalyst SD-WAN Controller; exploitation could allow an attacker to disrupt or manipulate SD-WAN fabric operations, making patching urgent for any organization running this infrastructure.
4
A companion to CVE-2026-20303, this Cisco Catalyst SD-WAN Controller flaw involves improper access control, potentially letting an attacker access privileged functionality without proper authorization — a critical concern for wide-area network administrators.
5
Progress MarkLogic Server's Hadoop integration allows an authenticated user holding only a low-privileged Hadoop role to escalate privileges and execute operations against the sensitive Security database; patching to versions 11.3.6 or 12.0.3 is the only reliable mitigation.
6
A second MarkLogic privilege escalation flaw, this time via the REST API document patch operation, enables a low-privileged REST user to reach the Security database with elevated rights — organizations running the REST API surface are directly exposed.
7
The third MarkLogic privilege escalation in today's batch affects SQL, SPARQL, and Optic REST query interfaces, allowing a low-privileged REST user to fully escalate to administrator and access unauthorized data; all three MarkLogic CVEs should be treated as a single patching priority.
8
OpenPLC Runtime v3's compile_program() function processes attacker-uploaded Structured Text files without validating file paths, enabling a path traversal write to arbitrary locations such as cron.d — on a running industrial control system, this could translate to remote code execution with severe operational consequences.
9
A classic SQL injection and authentication bypass in Stock-Inventory-Management-System's login.php allows an unauthenticated attacker to access the application entirely by submitting a trivial payload; the low complexity and unauthenticated nature make this a prime candidate for rapid weaponization.
10
The PlanDev sequencing-server's authorization middleware trusts a caller-supplied session_variables JSON object over verified JWT claims, allowing any unauthenticated caller to self-assign an admin role — a complete authentication bypass that exposes all privileged sequencing operations.
Ransomware today
Ransomware activity against Brazilian targets has been notably active recently, with four new victims identified: PontoBR Sistemas and eSysTech (Technology sector) hit by spacebears and Orova respectively, cesmac.edu.br (Education) targeted by krybit, and rai.com.br claimed by lockbit5. Over the past 30 days, lockbit5 leads all groups with 24 confirmed victims — all in Brazil — making it the most immediate threat to Brazilian organizations across sectors.
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs
Several threat actor groups have been flagged as active or updated in the current period, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel, though no specific victims have been publicly attributed to them at this time. Their presence in threat intelligence feeds warrants monitoring, particularly krybit given its confirmed ransomware activity against a Brazilian educational institution.
Brazil focus
Brazil continues to face intense and cross-sector ransomware pressure over the past 30 days, with confirmed victims spanning Technology (PontoBR Sistemas, eSysTech), Education (cesmac.edu.br), Healthcare (SPDM via Global Secret Group), Energy (Sinop Energia via Global Secret Group), Government (Municipal Chamber of Serra via thegentlemen), and Professional Services (CRB group via thegentlemen). The concentration of lockbit5 activity exclusively within Brazil — 24 of its 24 known recent victims are Brazilian — signals a deliberate targeting campaign that organizations in the country must treat as an elevated and ongoing threat.
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
CRB groupthegentlemen · Professional Services
The Municipal Chamber of Serrathegentlemen · Government & Defense
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Organizations should prioritize patching Progress MarkLogic Server to versions 11.3.6 or 12.0.3 to address all three privilege escalation paths, update Cisco Catalyst SD-WAN Controller to the hardened release, and audit GitHub Actions workflows in PraisonAI deployments for unquoted branch name usage. For OpenPLC and inventory management systems exposed to the internet, immediate access restriction is warranted given the trivial exploitation paths involved.
Even when no active exploitation is confirmed, understanding which of these vulnerabilities exist in your own environment is the critical first step — organizations that proactively map and test their attack surface can act before threat actors do.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →