Daily briefing · August 7, 2026

Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under Fire

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical1 weaponized

August 7, 2026 carries a CRITICAL verdict: all ten highlighted vulnerabilities are confirmed under active exploitation by both CISA KEV and VulnCheck, spanning infrastructure pillars from edge appliances and CI/CD pipelines to content management and enterprise collaboration platforms. One exploit was weaponized within a single day of disclosure, and a WordPress chain attack reached weapon-ready status on the same day it was published, signaling an exceptionally aggressive threat landscape. Defenders must treat every item on today's list as an immediate patching priority, not a scheduled maintenance item.

Today’s brief
  • 10 CVEs under active exploitation confirmed by CISA KEV and VulnCheck simultaneously — no grace period for any of them
  • WordPress REST API + SQL injection chain (CVE-2026-63030) and SonicWall SMA1000 SSRF (CVE-2026-15409) weaponized within 24 hours of disclosure
  • Brazil faces a severe ransomware wave: 7 new victims in Manufacturing, Government, Education, and Technology sectors confirmed in recent days
  • Check Point SmartConsole auth bypass (CVE-2026-16232) arms attackers with full administrative privileges over security policies — weaponized same day
0
critical
10
Actively exploited
0
Before CISA
1
Weaponized
Critical highlights
1
CVE-2026-15409KEVCVSS 10Functional exploit1 daysaffects SMA1000
A CVSS 10.0 SSRF in SonicWall SMA1000's Work Place interface lets unauthenticated remote attackers force the appliance to reach internal or unintended destinations — weaponized in just 1 day, with a functional exploit confirmed. Any internet-exposed SMA1000 should be considered actively targeted.
2
CVE-2026-56291KEVCVSS 10Functional exploit2 daysaffects balbooa.com Balbooa Forms extension for Joomla
An unauthenticated arbitrary file upload in Balbooa Forms for Joomla (versions before 2.4.1) enables direct remote code execution without credentials — functional exploit confirmed and weaponized in 2 days. Sites running this extension are trivially compromisable and should update or disable the extension immediately.
3
CVE-2026-16812KEVCVSS 10affects VeloCloud Orchestrator On-Prem
VeloCloud Orchestrator On-Prem exposes privileged internal functionality to remote unauthenticated attackers, threatening full confidentiality, integrity, and availability of the orchestrator and all managed network data. This CVE carries CVSS 10.0 and is actively exploited despite a low EPSS score, underscoring that EPSS alone is insufficient for triage.
4
CVE-2026-63030KEVCVSS 9.8Weaponizedsame dayaffects WordPress
A chained attack combining REST API route confusion with a SQL injection flaw (CVE-2026-60137) in WordPress 6.9.x/7.0.x achieves full RCE — weaponized on the day of disclosure with a PoC carrying 721 GitHub stars and an EPSS of 98%. Any unpatched WordPress installation in the affected version ranges is at extreme risk.
5
CVE-2026-50522KEVCVSS 9.8PoC8 daysaffects Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated remote code execution over the network, with a proof of concept published and exploitation confirmed within 8 days. Organizations still running on-premises SharePoint 2016 without this patch face a well-documented and actively abused attack path.
6
CVE-2026-9198KEVCVSS 9.8Functional exploit4 daysaffects Langflow OSS
IBM Langflow OSS (versions 1.0.0–1.10.0) allows unauthenticated attackers to chain an auto-login endpoint that mints superuser tokens with a code-execution endpoint, achieving full RCE on default deployments — weaponized in 4 days with a functional exploit. AI/ML pipeline infrastructure is increasingly targeted and this flaw exemplifies why such services must never be exposed without authentication controls.
7
CVE-2026-58644KEVCVSS 9.8affects Microsoft SharePoint Enterprise Server 2016
A second deserialization RCE in Microsoft SharePoint Enterprise Server 2016 joins CVE-2026-50522 on today's list, both actively exploited — doubling the pressure on SharePoint defenders who may have patched one but not the other. Confirm both patches are applied before marking this platform as remediated.
8
CVE-2026-63077KEVCVSS 9.8PoC3 daysaffects TeamCity
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 is vulnerable to unauthenticated RCE via the agent polling protocol, weaponized in 3 days with a proof of concept. CI/CD servers are high-value targets because compromising them enables supply-chain-level access to build artifacts and deployment pipelines.
9
CVE-2026-16232KEVCVSS 9.3Functional exploitsame dayaffects Multi-Domain Security Management
An authentication bypass in Check Point SmartConsole's login process lets an unauthenticated remote attacker obtain an application token and authenticate with full administrative privileges, allowing arbitrary modification of security policies — weaponized on the same day of disclosure. Compromising the management plane of a firewall platform is as damaging as it gets.
10
CVE-2026-18577KEVHIGH 8.2PoC2 daysaffects N-central
An incomplete patch for CVE-2026-18556 in N-central (through version 2026.3.1) still allows authentication bypass and full account takeover — weaponized in 2 days. Incomplete patches that reopen previously known vulnerability classes are particularly dangerous because defenders may mistakenly believe they are already protected.
Ransomware today

Seven Brazilian organizations were recently confirmed as ransomware victims across critical sectors: Alya Construtora (Manufacturing, ransomhouse), Intranet Gov Brasil (Government & Defense, thegentlemen), brdigital.net.br and PontoBR Sistemas and eSysTech (Technology, L Group / spacebears / Orova), and uva.edu.br and cesmac.edu.br (Education, L Group / krybit). The 30-day activity ranking is dominated by lockbit5 with 24 victims — all in Brazil — followed by Section9 (6), Global Secret Group (4), qilin (3), Deadlock (3), and thegentlemen (3), all with their confirmed victims exclusively in Brazil, indicating a highly focused and sustained campaign against Brazilian targets.

Alya Construtora BRransomhouse · Manufacturing
Intranet Gov Brasil BRthegentlemen · Government & Defense
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 3
Active groups & APTs

Several threat actor groups are currently tracked as active or recently updated: againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are attributed to these actors in the current window, their active status in threat intelligence feeds warrants monitoring, particularly krybit which also appears in the ransomware victim data targeting Brazilian education institutions.

Brazil focus

Brazil is under acute pressure on multiple fronts simultaneously: ransomware groups are actively claiming victims in government, education, technology, and manufacturing sectors, while the CVEs highlighted today directly threaten infrastructure widely deployed in the country, including SharePoint, WordPress, and network management platforms. The confirmed attack on Intranet Gov Brasil by thegentlemen is especially notable given its government and defense classification, and rai.com.br (Other sector) attributed to the prolific lockbit5 adds to a pattern of broad-spectrum targeting that shows no sign of slowing.

brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Prioritize immediate patching or mitigation for all ten CVEs, starting with the four weaponized on or within one day of disclosure (CVE-2026-15409, CVE-2026-63030, CVE-2026-16232, CVE-2026-56291) and verify that internet-facing management interfaces — firewall consoles, CI/CD servers, orchestrators, and AI pipeline endpoints — are not directly reachable without authentication. Organizations running SharePoint 2016 must confirm both CVE-2026-50522 and CVE-2026-58644 are patched, as both are actively exploited concurrently.
With ten actively exploited critical vulnerabilities spanning edge appliances, CMS platforms, CI/CD pipelines, and enterprise collaboration tools, now is the moment to validate whether your actual exposure matches your assumed patch posture — the gap between the two is where attackers are operating today.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →