Daily briefing · August 5, 2026
Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 5, 2026 brought 400 new CVEs — 45 of them critical — yet no active exploitation or weaponized proof-of-concept code was confirmed for any of them, keeping the overall threat level calm. The day's highlights center on three high-impact product families: Cisco Catalyst SD-WAN Controller, Progress MarkLogic Server, and a cluster of critical flaws in tools ranging from OpenPLC Runtime to AI-agent framework PraisonAI. While no weaponized exploits are in circulation today, the severity scores and attack vectors demand immediate patching attention before that changes.
Today’s brief
- 45 critical CVEs published today — none yet confirmed in active exploitation or with a ready-made exploit module
- Cisco Catalyst SD-WAN Controller carries two CVSS 9.9 flaws (improper input validation and access control) requiring urgent patching in SD-WAN deployments
- Progress MarkLogic Server has three separate CVSS 9.9 privilege escalation paths — Hadoop, REST API patch, and SQL/SPARQL interfaces — all fixed in versions 11.3.6 and 12.0.3
- Brazil is under sustained ransomware pressure: four new victims confirmed recently, with lockbit5 leading the 30-day ranking
Critical highlights
1
A command injection vulnerability in PraisonAI's bundled Claude GitHub Actions workflow allows an attacker to inject arbitrary shell commands via a crafted pull request branch name, since the value is embedded in a Bash block without quoting or validation; any commenter can trigger the job, making this a serious supply-chain risk for teams using PraisonAI in CI/CD pipelines.
2
CVE-2026-10090CVSS 9.9affects Red Hat Advanced Cluster Management for Kubernetes 2 A CVSS 9.9 flaw in Red Hat ACM's Application Subscription controller lets a user with only namespace-scoped edit privileges create a malicious Helm Channel and Subscription, causing the app-subscription controller to fetch and apply attacker-controlled Helm charts — effectively granting cluster-level impact from minimal permissions.
3
Cisco's own internal security review uncovered improper input validation vulnerabilities in the Catalyst SD-WAN Controller; exploitation could allow an attacker to disrupt or manipulate SD-WAN fabric operations, making patching urgent for any organization running this infrastructure.
4
A companion to CVE-2026-20303, this Cisco Catalyst SD-WAN Controller flaw involves improper access control, potentially letting an attacker access privileged functionality without proper authorization — a critical concern for wide-area network administrators.
5
Progress MarkLogic Server's Hadoop integration allows an authenticated user holding only a low-privileged Hadoop role to escalate privileges and execute operations against the sensitive Security database; patching to versions 11.3.6 or 12.0.3 is the only reliable mitigation.
6
A second MarkLogic privilege escalation flaw, this time via the REST API document patch operation, enables a low-privileged REST user to reach the Security database with elevated rights — organizations running the REST API surface are directly exposed.
7
The third MarkLogic privilege escalation in today's batch affects SQL, SPARQL, and Optic REST query interfaces, allowing a low-privileged REST user to fully escalate to administrator and access unauthorized data; all three MarkLogic CVEs should be treated as a single patching priority.
8
OpenPLC Runtime v3's compile_program() function processes attacker-uploaded Structured Text files without validating file paths, enabling a path traversal write to arbitrary locations such as cron.d — on a running industrial control system, this could translate to remote code execution with severe operational consequences.
9
A classic SQL injection and authentication bypass in Stock-Inventory-Management-System's login.php allows an unauthenticated attacker to access the application entirely by submitting a trivial payload; the low complexity and unauthenticated nature make this a prime candidate for rapid weaponization.
10
The PlanDev sequencing-server's authorization middleware trusts a caller-supplied session_variables JSON object over verified JWT claims, allowing any unauthenticated caller to self-assign an admin role — a complete authentication bypass that exposes all privileged sequencing operations.
Ransomware today
Ransomware activity against Brazilian targets has been notably active recently, with four new victims identified: PontoBR Sistemas and eSysTech (Technology sector) hit by spacebears and Orova respectively, cesmac.edu.br (Education) targeted by krybit, and rai.com.br claimed by lockbit5. Over the past 30 days, lockbit5 leads all groups with 24 confirmed victims — all in Brazil — making it the most immediate threat to Brazilian organizations across sectors.
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs
Several threat actor groups have been flagged as active or updated in the current period, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel, though no specific victims have been publicly attributed to them at this time. Their presence in threat intelligence feeds warrants monitoring, particularly krybit given its confirmed ransomware activity against a Brazilian educational institution.
Brazil focus
Brazil continues to face intense and cross-sector ransomware pressure over the past 30 days, with confirmed victims spanning Technology (PontoBR Sistemas, eSysTech), Education (cesmac.edu.br), Healthcare (SPDM via Global Secret Group), Energy (Sinop Energia via Global Secret Group), Government (Municipal Chamber of Serra via thegentlemen), and Professional Services (CRB group via thegentlemen). The concentration of lockbit5 activity exclusively within Brazil — 24 of its 24 known recent victims are Brazilian — signals a deliberate targeting campaign that organizations in the country must treat as an elevated and ongoing threat.
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
CRB groupthegentlemen · Professional Services
The Municipal Chamber of Serrathegentlemen · Government & Defense
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Organizations should prioritize patching Progress MarkLogic Server to versions 11.3.6 or 12.0.3 to address all three privilege escalation paths, update Cisco Catalyst SD-WAN Controller to the hardened release, and audit GitHub Actions workflows in PraisonAI deployments for unquoted branch name usage. For OpenPLC and inventory management systems exposed to the internet, immediate access restriction is warranted given the trivial exploitation paths involved.
Even when no active exploitation is confirmed, understanding which of these vulnerabilities exist in your own environment is the critical first step — organizations that proactively map and test their attack surface can act before threat actors do.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →