Daily briefing · August 6, 2026

10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and More

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical1 weaponized

August 6, 2026 carries a CRITICAL verdict: ten vulnerabilities are confirmed under active exploitation by both CISA KEV and VulnCheck, spanning enterprise platforms from WordPress and Microsoft SharePoint to SonicWall SMA1000, VMware VeloCloud, and JetBrains TeamCity. One exploit was fully weaponized within a single day of disclosure, and two others were armed within 48 hours, signaling that attackers are moving at unprecedented speed to operationalize these flaws. Defenders face a wide and urgent attack surface requiring immediate triage across multiple product families.

Today’s brief
  • CRITICAL: 10 CVEs in active exploitation confirmed by CISA KEV and VulnCheck simultaneously — patch windows are measured in hours, not days
  • CVE-2026-63030 (WordPress RCE via SQL Injection) was weaponized the same day it was disclosed and carries a 98% EPSS score — immediate patching is non-negotiable
  • CVE-2026-15409 (SonicWall SMA1000 SSRF, CVSS 10.0) and CVE-2026-56291 (Joomla Balbooa Forms RCE, CVSS 10.0) both reached weaponized status within 1–2 days
  • Brazil is under sustained ransomware pressure: lockbit5, spacebears, krybit, and Orova have all claimed Brazilian victims in the technology, education, and energy sectors
0
critical
10
Actively exploited
0
Before CISA
1
Weaponized
Critical highlights
1
CVE-2026-15409KEVCVSS 10Functional exploit1 daysaffects SMA1000
A CVSS 10.0 SSRF in SonicWall SMA1000's Work Place interface allows unauthenticated remote attackers to force the appliance to make arbitrary internal requests; weaponized in just one day with a functional exploit and confirmed active exploitation makes this an immediate, drop-everything patch priority for any organization running SMA1000.
2
CVE-2026-56291KEVCVSS 10Functional exploit2 daysaffects balbooa.com Balbooa Forms extension for Joomla
An unauthenticated arbitrary file upload in the Balbooa Forms Joomla extension (versions below 2.4.1) allows attackers to upload executable files and achieve full remote code execution; weaponized within two days and carrying a functional exploit, any internet-facing Joomla site with this extension installed is effectively owned until patched.
3
CVE-2026-16812KEVCVSS 10affects VeloCloud Orchestrator On-Prem
A critical access control flaw in VMware VeloCloud Orchestrator On-Prem exposes privileged internal functionality to unauthenticated remote attackers, threatening the confidentiality, integrity, and availability of all SD-WAN infrastructure managed by the orchestrator — confirmed in active exploitation despite a low EPSS score, underscoring that EPSS alone is insufficient for triage.
4
CVE-2026-63030KEVCVSS 9.8Weaponizedsame dayaffects WordPress
WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 are vulnerable to REST API route confusion chained with a SQL injection (CVE-2026-60137) enabling full RCE; with a 98% EPSS score, a weaponized PoC boasting 718 GitHub stars, and same-day armament, this is the highest-probability mass-exploitation event in this bulletin.
5
CVE-2026-50522KEVCVSS 9.8PoC8 daysaffects Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated remote code execution over the network; armed within 8 days and confirmed in active exploitation, SharePoint deployments not yet patched must be treated as potentially compromised.
6
CVE-2026-9198KEVCVSS 9.8Functional exploit4 daysaffects Langflow OSS
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a devastating two-step unauthenticated RCE chain: the auto_login endpoint mints superuser tokens to any network caller, which can then be used to execute arbitrary code via the code validation endpoint — default deployments are fully exposed and this functional exploit was in the wild within 4 days of disclosure.
7
CVE-2026-58644KEVCVSS 9.8affects Microsoft SharePoint Enterprise Server 2016
A second deserialization RCE in Microsoft SharePoint Enterprise Server 2016 (distinct from CVE-2026-50522) reinforces that SharePoint is a priority target in the current threat landscape; unauthenticated network exploitation is confirmed active and organizations should verify patch status immediately.
8
CVE-2026-63077KEVCVSS 9.8PoC3 daysaffects TeamCity
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 is vulnerable to unauthenticated remote code execution via the agent polling protocol; armed in 3 days with a proof of concept and confirmed in active exploitation, CI/CD pipeline compromise via TeamCity remains a high-value target for supply chain attacks.
9
CVE-2026-16232KEVCVSS 9.3Functional exploitsame dayaffects Multi-Domain Security Management
An authentication bypass in Check Point SmartConsole allows an unauthenticated remote attacker to obtain a valid application login token and gain full administrative privileges over security policy and configuration; weaponized on the same day of disclosure with a functional exploit, internet-exposed Check Point Management Servers are at extreme risk of complete security posture compromise.
10
CVE-2026-18577KEVHIGH 8.2PoC2 daysaffects N-central
An incomplete patch for CVE-2026-18556 in N-central (through version 2026.3.1) still allows authentication bypass and full account takeover; armed within 2 days with a proof of concept, this is a reminder that patch-bypass vulnerabilities in management platforms carry outsized risk since defenders may believe they are already protected.
Ransomware today

Several ransomware groups have recently claimed Brazilian victims across critical sectors. PontoBR Sistemas and eSysTech (Technology) were hit by spacebears and Orova respectively, while the educational institution cesmac.edu.br was claimed by krybit and rai.com.br by lockbit5. Over the past 30 days, lockbit5 has been the most prolific actor with 24 recorded victims — all in Brazil — making it the dominant ransomware threat to Brazilian organizations at this time.

PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
rai.com.br BRlockbit5 · Other
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 2
Active groups & APTs

Several threat actor groups are currently being tracked for potential activity: againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel have all been flagged as active or updated, though no confirmed victims have been publicly attributed to them at this time. Their presence in threat intelligence feeds suggests ongoing reconnaissance or preparation, and defenders should monitor for indicators associated with these groups, particularly given the volume of critical vulnerabilities currently available for exploitation.

Brazil focus

Brazil is facing intense and broadening ransomware pressure across multiple sectors. Recent victims include PontoBR Sistemas and eSysTech (Technology), cesmac.edu.br (Education), rai.com.br (Other), The Municipal Chamber of Serra and CRB group (Government and Professional Services targeted by thegentlemen), SPDM (Healthcare) and Sinop Energia (Energy and Utilities) both claimed by Global Secret Group. The concentration of attacks spanning government, healthcare, education, and critical infrastructure signals that Brazilian organizations of all sizes and sectors should treat the current threat level as elevated.

PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
The Municipal Chamber of Serrathegentlemen · Government & Defense
CRB groupthegentlemen · Professional Services
SPDMGlobal Secret Group · Healthcare
Sinop EnergiaGlobal Secret Group · Energy & Utilities
Today’s recommendation: Organizations must immediately audit patch status for all ten highlighted CVEs, prioritizing WordPress (CVE-2026-63030), SonicWall SMA1000 (CVE-2026-15409), both SharePoint CVEs, and TeamCity (CVE-2026-63077) — where patching is not immediately possible, block internet access to the affected interfaces and implement compensating controls such as WAF rules and network segmentation. Given the speed of weaponization observed (same-day to four days), treat any unpatched instance of these products as potentially compromised and initiate threat hunting in parallel with remediation.
With exploits reaching weapon-ready status in under 24 hours across this many product families, validating your own attack surface — not just assuming patches are in place — is the only way to know whether your organization is genuinely protected.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →