Daily briefing · August 7, 2026
Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under Fire
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical1 weaponized
August 7, 2026 carries a CRITICAL verdict: all ten highlighted vulnerabilities are confirmed under active exploitation by both CISA KEV and VulnCheck, spanning infrastructure pillars from edge appliances and CI/CD pipelines to content management and enterprise collaboration platforms. One exploit was weaponized within a single day of disclosure, and a WordPress chain attack reached weapon-ready status on the same day it was published, signaling an exceptionally aggressive threat landscape. Defenders must treat every item on today's list as an immediate patching priority, not a scheduled maintenance item.
Today’s brief
- 10 CVEs under active exploitation confirmed by CISA KEV and VulnCheck simultaneously — no grace period for any of them
- WordPress REST API + SQL injection chain (CVE-2026-63030) and SonicWall SMA1000 SSRF (CVE-2026-15409) weaponized within 24 hours of disclosure
- Brazil faces a severe ransomware wave: 7 new victims in Manufacturing, Government, Education, and Technology sectors confirmed in recent days
- Check Point SmartConsole auth bypass (CVE-2026-16232) arms attackers with full administrative privileges over security policies — weaponized same day
Critical highlights
1
A CVSS 10.0 SSRF in SonicWall SMA1000's Work Place interface lets unauthenticated remote attackers force the appliance to reach internal or unintended destinations — weaponized in just 1 day, with a functional exploit confirmed. Any internet-exposed SMA1000 should be considered actively targeted.
2
CVE-2026-56291KEVCVSS 10Functional exploit2 daysaffects balbooa.com Balbooa Forms extension for Joomla An unauthenticated arbitrary file upload in Balbooa Forms for Joomla (versions before 2.4.1) enables direct remote code execution without credentials — functional exploit confirmed and weaponized in 2 days. Sites running this extension are trivially compromisable and should update or disable the extension immediately.
3
VeloCloud Orchestrator On-Prem exposes privileged internal functionality to remote unauthenticated attackers, threatening full confidentiality, integrity, and availability of the orchestrator and all managed network data. This CVE carries CVSS 10.0 and is actively exploited despite a low EPSS score, underscoring that EPSS alone is insufficient for triage.
4
A chained attack combining REST API route confusion with a SQL injection flaw (CVE-2026-60137) in WordPress 6.9.x/7.0.x achieves full RCE — weaponized on the day of disclosure with a PoC carrying 721 GitHub stars and an EPSS of 98%. Any unpatched WordPress installation in the affected version ranges is at extreme risk.
5
CVE-2026-50522KEVCVSS 9.8PoC8 daysaffects Microsoft SharePoint Enterprise Server 2016 Deserialization of untrusted data in Microsoft SharePoint Enterprise Server 2016 allows unauthenticated remote code execution over the network, with a proof of concept published and exploitation confirmed within 8 days. Organizations still running on-premises SharePoint 2016 without this patch face a well-documented and actively abused attack path.
6
CVE-2026-9198KEVCVSS 9.8Functional exploit4 daysaffects Langflow OSS IBM Langflow OSS (versions 1.0.0–1.10.0) allows unauthenticated attackers to chain an auto-login endpoint that mints superuser tokens with a code-execution endpoint, achieving full RCE on default deployments — weaponized in 4 days with a functional exploit. AI/ML pipeline infrastructure is increasingly targeted and this flaw exemplifies why such services must never be exposed without authentication controls.
7
CVE-2026-58644KEVCVSS 9.8affects Microsoft SharePoint Enterprise Server 2016 A second deserialization RCE in Microsoft SharePoint Enterprise Server 2016 joins CVE-2026-50522 on today's list, both actively exploited — doubling the pressure on SharePoint defenders who may have patched one but not the other. Confirm both patches are applied before marking this platform as remediated.
8
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 is vulnerable to unauthenticated RCE via the agent polling protocol, weaponized in 3 days with a proof of concept. CI/CD servers are high-value targets because compromising them enables supply-chain-level access to build artifacts and deployment pipelines.
9
CVE-2026-16232KEVCVSS 9.3Functional exploitsame dayaffects Multi-Domain Security Management An authentication bypass in Check Point SmartConsole's login process lets an unauthenticated remote attacker obtain an application token and authenticate with full administrative privileges, allowing arbitrary modification of security policies — weaponized on the same day of disclosure. Compromising the management plane of a firewall platform is as damaging as it gets.
10
An incomplete patch for CVE-2026-18556 in N-central (through version 2026.3.1) still allows authentication bypass and full account takeover — weaponized in 2 days. Incomplete patches that reopen previously known vulnerability classes are particularly dangerous because defenders may mistakenly believe they are already protected.
Ransomware today
Seven Brazilian organizations were recently confirmed as ransomware victims across critical sectors: Alya Construtora (Manufacturing, ransomhouse), Intranet Gov Brasil (Government & Defense, thegentlemen), brdigital.net.br and PontoBR Sistemas and eSysTech (Technology, L Group / spacebears / Orova), and uva.edu.br and cesmac.edu.br (Education, L Group / krybit). The 30-day activity ranking is dominated by lockbit5 with 24 victims — all in Brazil — followed by Section9 (6), Global Secret Group (4), qilin (3), Deadlock (3), and thegentlemen (3), all with their confirmed victims exclusively in Brazil, indicating a highly focused and sustained campaign against Brazilian targets.
Alya Construtora BRransomhouse · Manufacturing
Intranet Gov Brasil BRthegentlemen · Government & Defense
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
cesmac.edu.br BRkrybit · Education
eSysTech BROrova · Technology
lockbit5 24Section9 6Global Secret Group 4qilin 3Deadlock 3thegentlemen 3
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated: againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victims are attributed to these actors in the current window, their active status in threat intelligence feeds warrants monitoring, particularly krybit which also appears in the ransomware victim data targeting Brazilian education institutions.
Brazil focus
Brazil is under acute pressure on multiple fronts simultaneously: ransomware groups are actively claiming victims in government, education, technology, and manufacturing sectors, while the CVEs highlighted today directly threaten infrastructure widely deployed in the country, including SharePoint, WordPress, and network management platforms. The confirmed attack on Intranet Gov Brasil by thegentlemen is especially notable given its government and defense classification, and rai.com.br (Other sector) attributed to the prolific lockbit5 adds to a pattern of broad-spectrum targeting that shows no sign of slowing.
brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Prioritize immediate patching or mitigation for all ten CVEs, starting with the four weaponized on or within one day of disclosure (CVE-2026-15409, CVE-2026-63030, CVE-2026-16232, CVE-2026-56291) and verify that internet-facing management interfaces — firewall consoles, CI/CD servers, orchestrators, and AI pipeline endpoints — are not directly reachable without authentication. Organizations running SharePoint 2016 must confirm both CVE-2026-50522 and CVE-2026-58644 are patched, as both are actively exploited concurrently.
With ten actively exploited critical vulnerabilities spanning edge appliances, CMS platforms, CI/CD pipelines, and enterprise collaboration tools, now is the moment to validate whether your actual exposure matches your assumed patch posture — the gap between the two is where attackers are operating today.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →