Daily briefing · August 9, 2026
August 9 Quiet Day: IoT Command Injection Flaws and Brazilian Ransomware Wave Dominate the Picture
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 9, 2026 registers a calm vulnerability landscape, with 78 new CVEs published, one rated Critical and none confirmed under active exploitation or flagged as weaponized. The highlight on the technical side is a cluster of proof-of-concept command injection and buffer overflow flaws hitting consumer-grade networking devices and embedded systems. Meanwhile, the ransomware intelligence picture tells a more urgent story, with multiple Brazilian organizations across government, education, and technology sectors listed as recent victims.
Today’s brief
- No CVEs reached weaponized or KEV status on this date — the day is technically calm
- A critical command injection in Shenzhen Aitemi M300 Wi-Fi Repeater tops the list with a 9.3 CVSS and a public PoC
- Brazilian entities — including a government intranet, a university, and a tech provider — appear as fresh ransomware victims
- GStreamer vulnerabilities in Red Hat Enterprise Linux 10 could enable memory corruption or code execution via crafted media files
Critical highlights
1
A critical command injection flaw in the Shenzhen Aitemi M300 Wi-Fi Repeater allows unauthenticated remote attackers to inject OS commands via the enable, name, or mac parameters; a public proof-of-concept is available, making this an immediate patching priority for environments using this device.
2
The Tenda CH22 router is vulnerable to remote command injection through the Name argument of the CertListInfo endpoint; with a public exploit already circulating, unpatched devices on perimeter networks face a realistic takeover risk.
3
A stack-based buffer overflow in the UTT HiPER 1200GW router's PPP configuration handler can be triggered remotely by manipulating the EncryptionMode argument; the vendor was notified but did not respond, leaving users without an official fix path.
4
A local privilege escalation flaw in Kingston FURY CTRL RGB Control Software abuses the NTIOLib_KSFX.sys kernel driver due to improper privilege management; attackers with local access can elevate to SYSTEM, and the vendor has not issued a patch.
5
A heap out-of-bounds write in GStreamer's ADPCM audio decoder can be triggered by a crafted WAV file, potentially leading to memory corruption or arbitrary code execution on Red Hat Enterprise Linux 10 and other affected platforms.
6
A path traversal vulnerability in parisneo/lollms 2.1.0 allows remote attackers to read arbitrary files from the server by using URL-encoded dot-dot sequences that bypass built-in path normalization; exposure depends on how the service is deployed.
7
Multiple integer overflow and underflow flaws in GStreamer's ASF demuxer can be triggered by crafted ASF, WMV, or WMA files, potentially causing heap out-of-bounds reads leading to application crashes or limited information disclosure.
8
A SQL injection vulnerability in SourceCodester Simple Doctors Appointment System 1.0 can be exploited remotely via the ID parameter of the appointment-setting endpoint; a public exploit exists, posing a direct data exposure risk for any publicly accessible deployment.
9
An OS command injection flaw in the EFM ipTIME AX8004M router's CGI endpoint allows remote manipulation of the fname argument to execute arbitrary commands; the vendor did not respond to coordinated disclosure, meaning no official patch is available.
10
A permission management flaw in Uasoft Badaso 3.0.0-alpha's File API can be exploited remotely to perform unauthorized operations; a public exploit has been disclosed and the project has been notified.
Ransomware today
Ransomware activity targeting Brazilian organizations has intensified recently, with thegentlemen claiming Intranet Gov Brasil in the government sector, ransomhouse listing Alya Construtora in manufacturing, and L Group taking credit for both brdigital.net.br and uva.edu.br in the technology and education sectors respectively. Over the past 30 days, lockbit5 leads overall activity with 24 claimed victims — all in Brazil — followed by Section9 with 6 Brazilian victims and Global Secret Group with 4, underscoring that Brazil remains a primary target for multiple active ransomware operations.
Intranet Gov Brasil BRthegentlemen · Government & Defense
Alya Construtora BRransomhouse · Manufacturing
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
lockbit5 24Section9 6Global Secret Group 4Deadlock 3thegentlemen 3L Group 2
Active groups & APTs
Several notable threat actors are being tracked without confirmed new victims at this time, including Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, linkc, and apt73. While no fresh victims are attributed to these groups in the current window, their continued monitoring reflects ongoing intelligence interest in their tooling and targeting patterns.
Brazil focus
Brazil is facing a concentrated wave of ransomware incidents across critical sectors: thegentlemen hit a government intranet, L Group compromised both a tech provider and a university (uva.edu.br), and ransomhouse targeted Alya Construtora in manufacturing. Extending the window to the past 30 days reveals additional victims including cesmac.edu.br, eSysTech, PontoBR Sistemas, and rai.com.br, with lockbit5 standing out as the most prolific actor against Brazilian targets.
Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Security teams should prioritize patching or isolating the affected consumer and SMB networking devices — particularly Tenda CH22, UTT HiPER 1200GW, and ipTIME AX8004M — given that public proof-of-concept exploits are already available; organizations running GStreamer-based media pipelines on Red Hat Enterprise Linux 10 should also evaluate exposure to the ADPCM and ASF demuxer flaws ahead of formal patches.
Regardless of the day's technical calm, the active ransomware pressure against Brazilian organizations is a strong reminder to continuously validate your own attack surface and assess whether your exposure aligns with what you assume it to be.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 8, 2026 — MSI Router Hit by Eight Critical Command Injection CVEs; WordPress AI Plugin Opens Admin BackdoorAugust 7, 2026 — Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under FireAugust 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple Groupsview full archive →