Daily briefing · August 12, 2026

LXD Hit by Five Critical Flaws, Joomla and Prompty Join a Busy Patch Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 12, 2026 brings a calm day in terms of active exploitation — no CVEs were weaponized, none confirmed in the wild — but the vulnerability disclosure volume tells a different story: 400 new CVEs published, 51 rated critical. The standouts demand immediate attention from defenders running container infrastructure, Joomla deployments, and AI-adjacent tooling.

Today’s brief
  • No active exploitation confirmed today, but 51 critical CVEs published — patch prioritization is key
  • LXD receives five critical vulnerabilities spanning path traversal, symlink attacks, and authorization bypass — container environments at high risk
  • Joomla Fabrik extension exposes unauthenticated RCE (CVSS 10.0) — any internet-facing instance should be considered compromised until patched
  • Brazil continues to be heavily targeted by ransomware groups, with victims spanning government, legal, education, and tech sectors
51
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-67282CVSS 10affects Fabrik extension for Joomla
A CVSS 10.0 unauthenticated remote code execution flaw in the Fabrik extension for Joomla (versions before 4.6.8) allows any external attacker to execute arbitrary code via the frontend listfilter model — no credentials required, making every exposed Joomla site with Fabrik installed an immediate target.
2
CVE-2024-27253CVSS 10affects DOORS Next
IBM DOORS Next 7.0.3 through Interim Fix 018 contains an authentication bypass allowing a logged-in user to circumvent security logic and perform unauthorized operations — in requirements management environments, this could mean unauthorized modification of safety-critical documentation.
3
CVE-2026-73299CVSS 10affects prompty
The Prompty TypeScript Nunjucks renderer (before 0.1.5 and 2.0.0-beta.5) allows untrusted .prompty template files to traverse prototype chains and execute arbitrary JavaScript in the host Node.js process — any pipeline that processes externally sourced or user-submitted prompt templates is at risk of full server-side code execution.
4
CVE-2026-66898CVSS 9.9affects LXD
A path traversal vulnerability in LXD allows an attacker who can supply a crafted backup archive to manipulate file system paths during import or restore operations, potentially writing files outside intended boundaries on the host — especially dangerous in multi-tenant or shared infrastructure environments.
5
CVE-2026-63293CVSS 9.9affects LXD
A symlink-following flaw in LXD lets an attacker embed a malicious symbolic link in place of the metadata.yaml file within an image archive, enabling arbitrary file read and write on the host system — access to host file system from a container context is a critical containment breach.
6
CVE-2026-63294CVSS 9.9affects LXD
A second symlink vulnerability in LXD, this time targeting backup.yaml, escalates the impact further by enabling root-level command execution on the host — a crafted archive processed during import can result in full host compromise with highest privileges.
7
CVE-2026-72508CVSS 9.9affects Red Hat Advanced Cluster Management for Kubernetes 2
A confused-deputy vulnerability in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management for Kubernetes 2 allows a namespace-admin tenant to abuse a highly privileged ServiceAccount by crafting Subscription CRs, enabling deployment of arbitrary cluster-scoped resources and privilege escalation to cluster-admin — a serious risk in shared Kubernetes management planes.
8
CVE-2026-63296CVSS 9.9affects LXD
An authorization bypass in LXD permits an authenticated attacker to override project security restrictions during instance migration by supplying configuration overrides that are not validated against the target project's enforced policy — effectively allowing high-privilege instances to be smuggled into restricted projects.
9
CVE-2026-63297CVSS 9.9affects LXD
A TOCTOU (time-of-check to time-of-use) race condition in LXD's configuration merging during cross-project instance copies allows an attacker to pass restriction checks before disallowed configuration is fully merged — exploitation can result in bypassing project-level security boundaries in containerized environments.
10
CVE-2026-62420CVSS 9.9affects LXD
A third authorization bypass in LXD affects cross-project instance migrations when a target cluster member is specified — the destination node entirely skips project restriction checks, allowing an authenticated attacker to move instances with disallowed privilege configurations to any target project without enforcement.
Ransomware today

The direwolf group has recently claimed Chat Jurídico, a Brazilian legal services firm, as a victim — a sector that handles sensitive privileged communications and client data. Over the past 30 days, lockbit5 has been the most active group globally with 21 victims, including 21 in Brazil, followed by Section9 (6), Global Secret Group (4), thegentlemen (3), L Group (2), and ransomhouse (2).

Chat Jurídico BRdirewolf · Professional Services
lockbit5 21Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs

Several threat actors are currently tracked as active or recently updated in threat intelligence feeds, including linkc, Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, and apt73. While no confirmed victims are linked to these groups in the current window, their presence in tracking systems warrants monitoring — particularly Darkhotel and Equation, which have historically targeted high-value government and enterprise environments.

Brazil focus

Brazil is facing an intense ransomware campaign period, with recent victims spanning multiple critical sectors: Chat Jurídico (Professional Services, direwolf), uva.edu.br (Education, L Group), Alya Construtora (Manufacturing, ransomhouse), brdigital.net.br (Technology, L Group), Intranet Gov Brasil (Government & Defense, thegentlemen), PontoBR Sistemas (Technology, spacebears), cesmac.edu.br (Education, krybit), and eSysTech (Technology, Orova). The breadth of targeted sectors — from government infrastructure to education and legal services — signals that Brazilian organizations across industries must treat ransomware preparedness as an immediate operational priority.

Chat Jurídicodirewolf · Professional Services
uva.edu.brL Group · Education
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
Intranet Gov Brasilthegentlemen · Government & Defense
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Organizations running LXD should apply available patches immediately and restrict who can import or restore backup and image archives — untrusted archive handling represents the highest-risk attack surface. Joomla administrators with the Fabrik extension installed should upgrade to 4.6.8 or disable the extension until patching is confirmed.
Given the volume of critical disclosures published today — particularly in container orchestration and web extension layers — it is essential to validate whether your exposed attack surface includes any of the affected components before adversaries have the chance to weaponize these findings.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share