Daily briefing · August 8, 2026

MSI Router Hit by Eight Critical Command Injection CVEs; WordPress AI Plugin Opens Admin Backdoor

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 8, 2026 brings no active exploitation or weaponized exploits, keeping the day's verdict calm — but the vulnerability disclosures themselves are far from trivial. Eight critical command injection flaws across MSI Radix AXE6600 router firmware and a WordPress plugin flaw enabling unauthenticated admin takeover dominate the landscape, demanding prompt patching even in the absence of confirmed in-the-wild attacks. Defenders should treat the volume and severity of these disclosures as a clear signal to audit exposure now.

Today’s brief
  • Eight critical command injection CVEs disclosed in MSI Radix AXE6600 firmware v781521, each enabling remote root access via different router functions
  • WordPress AI Copilot plugin flaw (CVSS 9.8) allows unauthenticated attackers to create administrator accounts and fully take over sites
  • No active exploitation (KEV) or weaponized exploits confirmed today — but severity warrants immediate patching
  • Brazil faces active ransomware pressure, with government, education, and technology sectors hit recently by multiple groups
27
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-14526CVSS 9.8affects AI Copilot – Content Generator
An authorization bypass in the AI Copilot – Content Generator WordPress plugin (all versions through 1.5.6) lets any unauthenticated attacker create a new administrator account and achieve complete site takeover — the highest practical risk for WordPress site owners who haven't updated.
2
CVE-2026-71993CVSS 9.3affects Radix AXE6600
A command injection in the MSI Radix AXE6600 openvpn function allows remote attackers to execute arbitrary commands and gain root privileges on the router — one of eight critical flaws in the same firmware version that collectively expose the device across multiple attack surfaces.
3
CVE-2026-71992CVSS 9.3affects Radix AXE6600
The macfilter function in MSI Radix AXE6600 firmware v781521 is vulnerable to command injection, enabling remote root-level code execution; attackers can chain this with other disclosed flaws across the same device for maximum impact.
4
CVE-2026-71991CVSS 9.3affects Radix AXE6600
A command injection in the TelnetSSH function (Telnet configuration path) of MSI Radix AXE6600 allows remote attackers to inject and execute arbitrary commands, escalating to root — particularly risky if the Telnet interface is exposed to untrusted networks.
5
CVE-2026-71990CVSS 9.3affects Radix AXE6600
The SSH configuration path of the TelnetSSH function in MSI Radix AXE6600 carries an independent command injection vulnerability, granting remote root access through the SSH management interface without requiring prior authentication context.
6
CVE-2026-71989CVSS 9.3affects Radix AXE6600
The porTrigger function in MSI Radix AXE6600 firmware is vulnerable to command injection exploitable via the ALG interface, allowing remote attackers to obtain root privileges — another entry point in a router that is now mapped across eight critical weaknesses.
7
CVE-2026-71988CVSS 9.3affects Radix AXE6600
Command injection in the portFw (port forwarding) function of MSI Radix AXE6600 enables remote arbitrary command execution at root level, expanding the attack surface for anyone with network access to the device's management plane.
8
CVE-2026-71987CVSS 9.3affects Radix AXE6600
The alg function itself in MSI Radix AXE6600 is directly injectable, allowing root-level command execution; the repeated appearance of the ALG subsystem across multiple CVEs suggests a systemic input validation failure in this firmware branch.
9
CVE-2026-71986CVSS 9.3affects Radix AXE6600
A command injection flaw in the dmz function of MSI Radix AXE6600 firmware v781521 lets remote attackers execute arbitrary commands and gain root privileges, adding yet another exploitable path to an already heavily exposed device.
10
CVE-2026-71985CVSS 9.3affects Radix AXE6600
The accesscontrol function in MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability enabling remote root access — completing a set of eight critical flaws that, taken together, make this firmware version effectively indefensible without an urgent update.
Ransomware today

Several Brazilian organizations have been recently claimed as ransomware victims across multiple groups: thegentlemen targeted Intranet Gov Brasil (government sector), ransomhouse hit Alya Construtora (manufacturing), L Group claimed brdigital.net.br and uva.edu.br (technology and education), and spacebears listed PontoBR Sistemas (technology). Over the past 30 days, lockbit5 has been the most prolific actor with 24 victims, all in Brazil, followed by Section9 (6), Global Secret Group (4), and Deadlock (3).

Intranet Gov Brasil BRthegentlemen · Government & Defense
Alya Construtora BRransomhouse · Manufacturing
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
PontoBR Sistemas BRspacebears · Technology
lockbit5 24Section9 6Global Secret Group 4Deadlock 3thegentlemen 3L Group 2
Active groups & APTs

Several threat actor groups — including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel — have been flagged as active or recently updated, though no confirmed victims are attributed to them at this time. Their presence in threat intelligence feeds warrants monitoring, as low victim counts may reflect early-stage operations or unreported activity rather than inactivity.

Brazil focus

Brazil is under sustained ransomware pressure across critical sectors: recent victims include a government network (Intranet Gov Brasil), two educational institutions (uva.edu.br and cesmac.edu.br), and multiple technology companies (brdigital.net.br, PontoBR Sistemas, eSysTech). Groups such as lockbit5, L Group, krybit, Orova, and thegentlemen have all claimed Brazilian targets in the past 30 days, underscoring that no sector is outside the current targeting scope.

Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Organizations running MSI Radix AXE6600 routers should apply firmware updates immediately and restrict management interfaces to trusted networks; WordPress administrators should update the AI Copilot – Content Generator plugin to a patched version and audit for any unauthorized administrator accounts.
Even on a calm disclosure day, the breadth and severity of today's findings underscore why continuously validating your own attack surface — before threat actors do — is the only reliable defensive posture.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share