Daily briefing · August 11, 2026
Cisco ASA and Windows Under Active Exploitation as Five CVSS-10 Flaws Emerge
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA
August 11 demands immediate attention: four vulnerabilities are under active exploitation, two of them flagged by VulnCheck before official CISA confirmation, signaling real-world attacker activity ahead of the public advisory cycle. Cisco Secure Firewall ASA and Windows WinSock top the urgent list, while five newly published CVSS-10 flaws — spanning Adobe Campaign Classic, ColdFusion, and SIMULIA — expand the critical attack surface significantly. Defenders should treat today as a high-priority patch and triage day.
Today’s brief
- Cisco ASA (CVE-2026-20349) and Windows WinSock (CVE-2026-68820) are both confirmed in CISA KEV and actively exploited — patch immediately.
- Two Weaver E-cology SQL injection flaws were spotted by VulnCheck before CISA acted, indicating exploitation was already underway in the wild.
- Five CVSS-10 vulnerabilities published today cover Adobe Campaign Classic (×2), ColdFusion, SIMULIA Execution Engine, and LiquidJS — all enabling unauthenticated or zero-interaction RCE.
- Brazil is under sustained ransomware pressure, with eight organizations hit across government, education, technology, and legal services sectors recently.
Critical highlights
1
CVE-2026-20349KEVHIGH 8.6affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software An unauthenticated remote attacker can crash Cisco ASA and FTD devices by sending malformed SSL VPN traffic, triggering a denial-of-service reload — confirmed in active exploitation by both VulnCheck and CISA KEV, making this an immediate priority for any organization running remote-access VPN on Cisco hardware.
2
A use-after-free in the Windows Ancillary Function Driver for WinSock allows a local authorized attacker to escalate privileges — actively exploited and listed in CISA KEV, making it a critical post-compromise escalation tool that adversaries are already weaponizing against Windows 10 environments.
3
This SQL injection in Weaver E-cology 8.0 and 9.0 allows unauthenticated attackers to extract arbitrary data via UNION-based payloads in the HrmCareerApplyPerView.jsp endpoint — VulnCheck observed exploitation before CISA acted, meaning real attacks were already in progress when this CVE was published.
4
A second SQL injection in Weaver E-cology 8.0 via the SignatureDownLoad servlet lets unauthenticated attackers read arbitrary files from the server filesystem — also flagged by VulnCheck ahead of CISA, reinforcing that E-cology deployments are actively targeted and should be isolated or patched without delay.
5
LiquidJS versions prior to 10.26.0 allow arbitrary code execution through crafted templates, posing a serious risk to any application that processes user-supplied or externally sourced templates — upgrading to 10.26.0 is the only mitigation.
6
Adobe Campaign Classic carries a CVSS-10 incorrect authorization flaw enabling unauthenticated, zero-interaction arbitrary code execution in the current user context with scope change — organizations running marketing automation on ACC should treat this as a remote takeover risk.
7
A second CVSS-10 incorrect authorization vulnerability in Adobe Campaign Classic mirrors CVE-2026-71398 in severity and exploitation conditions — the dual nature of these flaws in the same product suggests a systemic authorization control failure requiring urgent vendor patches.
8
ColdFusion 2023 is affected by an OS command injection vulnerability enabling unauthenticated, zero-interaction remote code execution with scope change — ColdFusion has a well-documented history of rapid exploitation after disclosure, making this a high-urgency patch target.
9
A deserialization of untrusted data vulnerability in SIMULIA Execution Engine (releases 2023–2026) allows unauthenticated remote code execution — deserialization flaws in engineering and simulation platforms represent high-value targets for industrial espionage and sabotage actors.
10
Streambert's IPC handler improperly validates executable paths, allowing a compromised renderer process to execute arbitrary local binaries with the application's full privileges — Electron app privilege escalation paths are increasingly targeted, and users should update to version 2.5.0 immediately.
Ransomware today
The direwolf group recently claimed Chat Jurídico, a Brazilian legal services firm, as its latest victim. Among the most active ransomware operators over the past 30 days, lockbit5 leads with 21 confirmed victims — all in Brazil — followed by Section9 (6), Global Secret Group (4), thegentlemen (3), ransomhouse (2), and L Group (2), painting a picture of sustained and geographically concentrated campaign activity.
Chat Jurídico BRdirewolf · Professional Services
lockbit5 21Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated, including linkc, Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, and apt73 — none have newly confirmed victims in this reporting cycle, but their elevated operational status warrants continued monitoring, particularly Darkhotel given its history of targeting business travelers and high-value corporate networks.
Brazil focus
Brazil is experiencing a pronounced wave of ransomware attacks across multiple sectors: Chat Jurídico (Professional Services, direwolf), Intranet Gov Brasil (Government, thegentlemen), Alya Construtora (Manufacturing, ransomhouse), brdigital.net.br and PontoBR Sistemas (Technology, L Group and spacebears respectively), uva.edu.br and cesmac.edu.br (Education, L Group and krybit), and eSysTech (Technology, Orova) have all been claimed as victims recently, reflecting a broad targeting pattern that spans public institutions, academic organizations, and private enterprises alike.
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
uva.edu.brL Group · Education
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Prioritize patching CVE-2026-20349 on all Cisco ASA and FTD appliances and CVE-2026-68820 on Windows 10 endpoints immediately, as both are confirmed under active exploitation; in parallel, audit all Adobe Campaign Classic, ColdFusion 2023, and Weaver E-cology deployments for the CVSS-10 and pre-CISA-flagged flaws published today.
With actively exploited vulnerabilities spanning network perimeters, operating systems, and enterprise applications simultaneously, now is the moment to validate which of these affected products exist in your environment and confirm that your detection and response controls would catch an exploit attempt before it escalates.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →