Daily briefing · August 7, 2026

Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under Fire

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical1 weaponized

August 7, 2026 carries a CRITICAL verdict: all ten highlighted vulnerabilities are confirmed under active exploitation by both CISA KEV and VulnCheck, spanning infrastructure pillars from edge appliances and CI/CD pipelines to content management and enterprise collaboration platforms. One exploit was weaponized within a single day of disclosure, and a WordPress chain attack reached weapon-ready status on the same day it was published, signaling an exceptionally aggressive threat landscape. Defenders must treat every item on today's list as an immediate patching priority, not a scheduled maintenance item.

Today’s brief
  • 10 CVEs under active exploitation confirmed by CISA KEV and VulnCheck simultaneously — no grace period for any of them
  • WordPress REST API + SQL injection chain (CVE-2026-63030) and SonicWall SMA1000 SSRF (CVE-2026-15409) weaponized within 24 hours of disclosure
  • Brazil faces a severe ransomware wave: 7 new victims in Manufacturing, Government, Education, and Technology sectors confirmed in recent days
  • Check Point SmartConsole auth bypass (CVE-2026-16232) arms attackers with full administrative privileges over security policies — weaponized same day
0
critical
10
Actively exploited
0
Before CISA
1
Weaponized
Critical highlights
1
CVE-2026-15409KEVCVSS 10Functional exploit1 daysaffects SMA1000
A CVSS 10.0 SSRF in SonicWall SMA1000's Work Place interface lets unauthenticated remote attackers force the appliance to reach internal or unintended destinations — weaponized in just 1 day, with a functional exploit confirmed. Any internet-exposed SMA1000 should be considered actively targeted.
2
CVE-2026-56291KEVCVSS 10Functional exploit2 daysaffects balbooa.com Balbooa Forms extension for Joomla
An unauthenticated arbitrary file upload in Balbooa Forms for Joomla (versions before 2.4.1) enables direct remote code execution without credentials — functional exploit confirmed and weaponized in 2 days. Sites running this extension are trivially compromisable and should update or disable the extension immediately.
3
CVE-2026-16812KEVCVSS 10affects VeloCloud Orchestrator On-Prem
VeloCloud Orchestrator On-Prem exposes privileged internal functionality to remote unauthenticated attackers, threatening full confidentiality, integrity, and availability of the orchestrator and all managed network data. This CVE carries CVSS 10.0 and is actively exploited despite a low EPSS score, underscoring that EPSS alone is insufficient for triage.
4
CVE-2026-63030KEVCVSS 9.8Weaponizedsame dayaffects WordPress
A chained attack combining REST API route confusion with a SQL injection flaw (CVE-2026-60137) in WordPress 6.9.x/7.0.x achieves full RCE — weaponized on the day of disclosure with a PoC carrying 721 GitHub stars and an EPSS of 98%. Any unpatched WordPress installation in the affected version ranges is at extreme risk.
5
CVE-2026-50522KEVCVSS 9.8PoC8 daysaffects Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated remote code execution over the network, with a proof of concept published and exploitation confirmed within 8 days. Organizations still running on-premises SharePoint 2016 without this patch face a well-documented and actively abused attack path.
6
CVE-2026-9198KEVCVSS 9.8Functional exploit4 daysaffects Langflow OSS
IBM Langflow OSS (versions 1.0.0–1.10.0) allows unauthenticated attackers to chain an auto-login endpoint that mints superuser tokens with a code-execution endpoint, achieving full RCE on default deployments — weaponized in 4 days with a functional exploit. AI/ML pipeline infrastructure is increasingly targeted and this flaw exemplifies why such services must never be exposed without authentication controls.
7
CVE-2026-58644KEVCVSS 9.8affects Microsoft SharePoint Enterprise Server 2016
A second deserialization RCE in Microsoft SharePoint Enterprise Server 2016 joins CVE-2026-50522 on today's list, both actively exploited — doubling the pressure on SharePoint defenders who may have patched one but not the other. Confirm both patches are applied before marking this platform as remediated.
8
CVE-2026-63077KEVCVSS 9.8PoC3 daysaffects TeamCity
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 is vulnerable to unauthenticated RCE via the agent polling protocol, weaponized in 3 days with a proof of concept. CI/CD servers are high-value targets because compromising them enables supply-chain-level access to build artifacts and deployment pipelines.
9
CVE-2026-16232KEVCVSS 9.3Functional exploitsame dayaffects Multi-Domain Security Management
An authentication bypass in Check Point SmartConsole's login process lets an unauthenticated remote attacker obtain an application token and authenticate with full administrative privileges, allowing arbitrary modification of security policies — weaponized on the same day of disclosure. Compromising the management plane of a firewall platform is as damaging as it gets.
10
CVE-2026-18577KEVHIGH 8.2PoC2 daysaffects N-central
An incomplete patch for CVE-2026-18556 in N-central (through version 2026.3.1) still allows authentication bypass and full account takeover — weaponized in 2 days. Incomplete patches that reopen previously known vulnerability classes are particularly dangerous because defenders may mistakenly believe they are already protected.
Ransomware today

Seven Brazilian organizations were recently confirmed as ransomware victims across critical sectors: Alya Construtora (Manufacturing, ransomhouse), Intranet Gov Brasil (Government & Defense, thegentlemen), brdigital.net.br and PontoBR Sistemas and eSysTech (Technology, L Group / spacebears / Orova), and uva.edu.br and cesmac.edu.br (Education, L Group / krybit). The 30-day activity ranking is dominated by lockbit5 with 24 victims — all in Brazil — followed by Section9 (6), Global Secret Group (4), qilin (3), Deadlock (3), and thegentlemen (3), all with their confirmed victims exclusively in Brazil, indicating a highly focused and sustained campaign against Brazilian targets.

Alya Construtora BRransomhouse · Manufacturing
Intranet Gov Brasil BRthegentlemen · Government & Defense
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 3
Active groups & APTs

Several threat actor groups are currently tracked as active or recently updated: againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are attributed to these actors in the current window, their active status in threat intelligence feeds warrants monitoring, particularly krybit which also appears in the ransomware victim data targeting Brazilian education institutions.

Brazil focus

Brazil is under acute pressure on multiple fronts simultaneously: ransomware groups are actively claiming victims in government, education, technology, and manufacturing sectors, while the CVEs highlighted today directly threaten infrastructure widely deployed in the country, including SharePoint, WordPress, and network management platforms. The confirmed attack on Intranet Gov Brasil by thegentlemen is especially notable given its government and defense classification, and rai.com.br (Other sector) attributed to the prolific lockbit5 adds to a pattern of broad-spectrum targeting that shows no sign of slowing.

brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Prioritize immediate patching or mitigation for all ten CVEs, starting with the four weaponized on or within one day of disclosure (CVE-2026-15409, CVE-2026-63030, CVE-2026-16232, CVE-2026-56291) and verify that internet-facing management interfaces — firewall consoles, CI/CD servers, orchestrators, and AI pipeline endpoints — are not directly reachable without authentication. Organizations running SharePoint 2016 must confirm both CVE-2026-50522 and CVE-2026-58644 are patched, as both are actively exploited concurrently.
With ten actively exploited critical vulnerabilities spanning edge appliances, CMS platforms, CI/CD pipelines, and enterprise collaboration tools, now is the moment to validate whether your actual exposure matches your assumed patch posture — the gap between the two is where attackers are operating today.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share