Daily briefing · August 6, 2026
10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and More
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical1 weaponized
August 6, 2026 carries a CRITICAL verdict: ten vulnerabilities are confirmed under active exploitation by both CISA KEV and VulnCheck, spanning enterprise platforms from WordPress and Microsoft SharePoint to SonicWall SMA1000, VMware VeloCloud, and JetBrains TeamCity. One exploit was fully weaponized within a single day of disclosure, and two others were armed within 48 hours, signaling that attackers are moving at unprecedented speed to operationalize these flaws. Defenders face a wide and urgent attack surface requiring immediate triage across multiple product families.
Today’s brief
- CRITICAL: 10 CVEs in active exploitation confirmed by CISA KEV and VulnCheck simultaneously — patch windows are measured in hours, not days
- CVE-2026-63030 (WordPress RCE via SQL Injection) was weaponized the same day it was disclosed and carries a 98% EPSS score — immediate patching is non-negotiable
- CVE-2026-15409 (SonicWall SMA1000 SSRF, CVSS 10.0) and CVE-2026-56291 (Joomla Balbooa Forms RCE, CVSS 10.0) both reached weaponized status within 1–2 days
- Brazil is under sustained ransomware pressure: lockbit5, spacebears, krybit, and Orova have all claimed Brazilian victims in the technology, education, and energy sectors
Critical highlights
1
A CVSS 10.0 SSRF in SonicWall SMA1000's Work Place interface allows unauthenticated remote attackers to force the appliance to make arbitrary internal requests; weaponized in just one day with a functional exploit and confirmed active exploitation makes this an immediate, drop-everything patch priority for any organization running SMA1000.
2
CVE-2026-56291KEVCVSS 10Functional exploit2 daysaffects balbooa.com Balbooa Forms extension for Joomla An unauthenticated arbitrary file upload in the Balbooa Forms Joomla extension (versions below 2.4.1) allows attackers to upload executable files and achieve full remote code execution; weaponized within two days and carrying a functional exploit, any internet-facing Joomla site with this extension installed is effectively owned until patched.
3
A critical access control flaw in VMware VeloCloud Orchestrator On-Prem exposes privileged internal functionality to unauthenticated remote attackers, threatening the confidentiality, integrity, and availability of all SD-WAN infrastructure managed by the orchestrator — confirmed in active exploitation despite a low EPSS score, underscoring that EPSS alone is insufficient for triage.
4
WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 are vulnerable to REST API route confusion chained with a SQL injection (CVE-2026-60137) enabling full RCE; with a 98% EPSS score, a weaponized PoC boasting 718 GitHub stars, and same-day armament, this is the highest-probability mass-exploitation event in this bulletin.
5
CVE-2026-50522KEVCVSS 9.8PoC8 daysaffects Microsoft SharePoint Enterprise Server 2016 Deserialization of untrusted data in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated remote code execution over the network; armed within 8 days and confirmed in active exploitation, SharePoint deployments not yet patched must be treated as potentially compromised.
6
CVE-2026-9198KEVCVSS 9.8Functional exploit4 daysaffects Langflow OSS IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a devastating two-step unauthenticated RCE chain: the auto_login endpoint mints superuser tokens to any network caller, which can then be used to execute arbitrary code via the code validation endpoint — default deployments are fully exposed and this functional exploit was in the wild within 4 days of disclosure.
7
CVE-2026-58644KEVCVSS 9.8affects Microsoft SharePoint Enterprise Server 2016 A second deserialization RCE in Microsoft SharePoint Enterprise Server 2016 (distinct from CVE-2026-50522) reinforces that SharePoint is a priority target in the current threat landscape; unauthenticated network exploitation is confirmed active and organizations should verify patch status immediately.
8
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 is vulnerable to unauthenticated remote code execution via the agent polling protocol; armed in 3 days with a proof of concept and confirmed in active exploitation, CI/CD pipeline compromise via TeamCity remains a high-value target for supply chain attacks.
9
CVE-2026-16232KEVCVSS 9.3Functional exploitsame dayaffects Multi-Domain Security Management An authentication bypass in Check Point SmartConsole allows an unauthenticated remote attacker to obtain a valid application login token and gain full administrative privileges over security policy and configuration; weaponized on the same day of disclosure with a functional exploit, internet-exposed Check Point Management Servers are at extreme risk of complete security posture compromise.
10
An incomplete patch for CVE-2026-18556 in N-central (through version 2026.3.1) still allows authentication bypass and full account takeover; armed within 2 days with a proof of concept, this is a reminder that patch-bypass vulnerabilities in management platforms carry outsized risk since defenders may believe they are already protected.
Ransomware today
Several ransomware groups have recently claimed Brazilian victims across critical sectors. PontoBR Sistemas and eSysTech (Technology) were hit by spacebears and Orova respectively, while the educational institution cesmac.edu.br was claimed by krybit and rai.com.br by lockbit5. Over the past 30 days, lockbit5 has been the most prolific actor with 24 recorded victims — all in Brazil — making it the dominant ransomware threat to Brazilian organizations at this time.
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs
Several threat actor groups are currently being tracked for potential activity: againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel have all been flagged as active or updated, though no confirmed victims have been publicly attributed to them at this time. Their presence in threat intelligence feeds suggests ongoing reconnaissance or preparation, and defenders should monitor for indicators associated with these groups, particularly given the volume of critical vulnerabilities currently available for exploitation.
Brazil focus
Brazil is facing intense and broadening ransomware pressure across multiple sectors. Recent victims include PontoBR Sistemas and eSysTech (Technology), cesmac.edu.br (Education), rai.com.br (Other), The Municipal Chamber of Serra and CRB group (Government and Professional Services targeted by thegentlemen), SPDM (Healthcare) and Sinop Energia (Energy and Utilities) both claimed by Global Secret Group. The concentration of attacks spanning government, healthcare, education, and critical infrastructure signals that Brazilian organizations of all sizes and sectors should treat the current threat level as elevated.
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Organizations must immediately audit patch status for all ten highlighted CVEs, prioritizing WordPress (CVE-2026-63030), SonicWall SMA1000 (CVE-2026-15409), both SharePoint CVEs, and TeamCity (CVE-2026-63077) — where patching is not immediately possible, block internet access to the affected interfaces and implement compensating controls such as WAF rules and network segmentation. Given the speed of weaponization observed (same-day to four days), treat any unpatched instance of these products as potentially compromised and initiate threat hunting in parallel with remediation.
With exploits reaching weapon-ready status in under 24 hours across this many product families, validating your own attack surface — not just assuming patches are in place — is the only way to know whether your organization is genuinely protected.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →