Daily briefing · August 9, 2026

August 9 Quiet Day: IoT Command Injection Flaws and Brazilian Ransomware Wave Dominate the Picture

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 9, 2026 registers a calm vulnerability landscape, with 78 new CVEs published, one rated Critical and none confirmed under active exploitation or flagged as weaponized. The highlight on the technical side is a cluster of proof-of-concept command injection and buffer overflow flaws hitting consumer-grade networking devices and embedded systems. Meanwhile, the ransomware intelligence picture tells a more urgent story, with multiple Brazilian organizations across government, education, and technology sectors listed as recent victims.

Today’s brief
  • No CVEs reached weaponized or KEV status on this date — the day is technically calm
  • A critical command injection in Shenzhen Aitemi M300 Wi-Fi Repeater tops the list with a 9.3 CVSS and a public PoC
  • Brazilian entities — including a government intranet, a university, and a tech provider — appear as fresh ransomware victims
  • GStreamer vulnerabilities in Red Hat Enterprise Linux 10 could enable memory corruption or code execution via crafted media files
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-19348CVSS 9.3PoCaffects M300 Wi-Fi Repeater
A critical command injection flaw in the Shenzhen Aitemi M300 Wi-Fi Repeater allows unauthenticated remote attackers to inject OS commands via the enable, name, or mac parameters; a public proof-of-concept is available, making this an immediate patching priority for environments using this device.
2
CVE-2026-19346HIGH 8.7PoCaffects CH22
The Tenda CH22 router is vulnerable to remote command injection through the Name argument of the CertListInfo endpoint; with a public exploit already circulating, unpatched devices on perimeter networks face a realistic takeover risk.
3
CVE-2026-19341HIGH 8.7PoCaffects HiPER 1200GW
A stack-based buffer overflow in the UTT HiPER 1200GW router's PPP configuration handler can be triggered remotely by manipulating the EncryptionMode argument; the vendor was notified but did not respond, leaving users without an official fix path.
4
CVE-2026-19381HIGH 8.5PoCaffects FURY CTRL RGB Control Software
A local privilege escalation flaw in Kingston FURY CTRL RGB Control Software abuses the NTIOLib_KSFX.sys kernel driver due to improper privilege management; attackers with local access can elevate to SYSTEM, and the vendor has not issued a patch.
5
CVE-2026-19387HIGH 7.6affects Red Hat Enterprise Linux 10
A heap out-of-bounds write in GStreamer's ADPCM audio decoder can be triggered by a crafted WAV file, potentially leading to memory corruption or arbitrary code execution on Red Hat Enterprise Linux 10 and other affected platforms.
6
CVE-2026-10595HIGH 7.5affects parisneo/lollms
A path traversal vulnerability in parisneo/lollms 2.1.0 allows remote attackers to read arbitrary files from the server by using URL-encoded dot-dot sequences that bypass built-in path normalization; exposure depends on how the service is deployed.
7
CVE-2026-19389HIGH 7.1affects Red Hat Enterprise Linux 10
Multiple integer overflow and underflow flaws in GStreamer's ASF demuxer can be triggered by crafted ASF, WMV, or WMA files, potentially causing heap out-of-bounds reads leading to application crashes or limited information disclosure.
8
CVE-2026-19384MEDIUM 6.9PoCaffects Simple Doctors Appointment System
A SQL injection vulnerability in SourceCodester Simple Doctors Appointment System 1.0 can be exploited remotely via the ID parameter of the appointment-setting endpoint; a public exploit exists, posing a direct data exposure risk for any publicly accessible deployment.
9
CVE-2026-19379MEDIUM 6.9PoCaffects ipTIME AX8004M
An OS command injection flaw in the EFM ipTIME AX8004M router's CGI endpoint allows remote manipulation of the fname argument to execute arbitrary commands; the vendor did not respond to coordinated disclosure, meaning no official patch is available.
10
CVE-2026-19376MEDIUM 6.9PoCaffects Badaso
A permission management flaw in Uasoft Badaso 3.0.0-alpha's File API can be exploited remotely to perform unauthorized operations; a public exploit has been disclosed and the project has been notified.
Ransomware today

Ransomware activity targeting Brazilian organizations has intensified recently, with thegentlemen claiming Intranet Gov Brasil in the government sector, ransomhouse listing Alya Construtora in manufacturing, and L Group taking credit for both brdigital.net.br and uva.edu.br in the technology and education sectors respectively. Over the past 30 days, lockbit5 leads overall activity with 24 claimed victims — all in Brazil — followed by Section9 with 6 Brazilian victims and Global Secret Group with 4, underscoring that Brazil remains a primary target for multiple active ransomware operations.

Intranet Gov Brasil BRthegentlemen · Government & Defense
Alya Construtora BRransomhouse · Manufacturing
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
lockbit5 24Section9 6Global Secret Group 4Deadlock 3thegentlemen 3L Group 2
Active groups & APTs

Several notable threat actors are being tracked without confirmed new victims at this time, including Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, linkc, and apt73. While no fresh victims are attributed to these groups in the current window, their continued monitoring reflects ongoing intelligence interest in their tooling and targeting patterns.

Brazil focus

Brazil is facing a concentrated wave of ransomware incidents across critical sectors: thegentlemen hit a government intranet, L Group compromised both a tech provider and a university (uva.edu.br), and ransomhouse targeted Alya Construtora in manufacturing. Extending the window to the past 30 days reveals additional victims including cesmac.edu.br, eSysTech, PontoBR Sistemas, and rai.com.br, with lockbit5 standing out as the most prolific actor against Brazilian targets.

Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
rai.com.brlockbit5 · Other
Today’s recommendation: Security teams should prioritize patching or isolating the affected consumer and SMB networking devices — particularly Tenda CH22, UTT HiPER 1200GW, and ipTIME AX8004M — given that public proof-of-concept exploits are already available; organizations running GStreamer-based media pipelines on Red Hat Enterprise Linux 10 should also evaluate exposure to the ADPCM and ASF demuxer flaws ahead of formal patches.
Regardless of the day's technical calm, the active ransomware pressure against Brazilian organizations is a strong reminder to continuously validate your own attack surface and assess whether your exposure aligns with what you assume it to be.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 8, 2026MSI Router Hit by Eight Critical Command Injection CVEs; WordPress AI Plugin Opens Admin BackdoorAugust 7, 2026Ten Critical CVEs Under Active Exploitation: SonicWall, WordPress, SharePoint, and More Under FireAugust 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple Groupsview full archive →