Daily briefing · August 12, 2026
LXD Hit by Five Critical Flaws, Joomla and Prompty Join a Busy Patch Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 12, 2026 brings a calm day in terms of active exploitation — no CVEs were weaponized, none confirmed in the wild — but the vulnerability disclosure volume tells a different story: 400 new CVEs published, 51 rated critical. The standouts demand immediate attention from defenders running container infrastructure, Joomla deployments, and AI-adjacent tooling.
Today’s brief
- No active exploitation confirmed today, but 51 critical CVEs published — patch prioritization is key
- LXD receives five critical vulnerabilities spanning path traversal, symlink attacks, and authorization bypass — container environments at high risk
- Joomla Fabrik extension exposes unauthenticated RCE (CVSS 10.0) — any internet-facing instance should be considered compromised until patched
- Brazil continues to be heavily targeted by ransomware groups, with victims spanning government, legal, education, and tech sectors
Critical highlights
1
A CVSS 10.0 unauthenticated remote code execution flaw in the Fabrik extension for Joomla (versions before 4.6.8) allows any external attacker to execute arbitrary code via the frontend listfilter model — no credentials required, making every exposed Joomla site with Fabrik installed an immediate target.
2
IBM DOORS Next 7.0.3 through Interim Fix 018 contains an authentication bypass allowing a logged-in user to circumvent security logic and perform unauthorized operations — in requirements management environments, this could mean unauthorized modification of safety-critical documentation.
3
The Prompty TypeScript Nunjucks renderer (before 0.1.5 and 2.0.0-beta.5) allows untrusted .prompty template files to traverse prototype chains and execute arbitrary JavaScript in the host Node.js process — any pipeline that processes externally sourced or user-submitted prompt templates is at risk of full server-side code execution.
4
A path traversal vulnerability in LXD allows an attacker who can supply a crafted backup archive to manipulate file system paths during import or restore operations, potentially writing files outside intended boundaries on the host — especially dangerous in multi-tenant or shared infrastructure environments.
5
A symlink-following flaw in LXD lets an attacker embed a malicious symbolic link in place of the metadata.yaml file within an image archive, enabling arbitrary file read and write on the host system — access to host file system from a container context is a critical containment breach.
6
A second symlink vulnerability in LXD, this time targeting backup.yaml, escalates the impact further by enabling root-level command execution on the host — a crafted archive processed during import can result in full host compromise with highest privileges.
7
CVE-2026-72508CVSS 9.9affects Red Hat Advanced Cluster Management for Kubernetes 2 A confused-deputy vulnerability in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management for Kubernetes 2 allows a namespace-admin tenant to abuse a highly privileged ServiceAccount by crafting Subscription CRs, enabling deployment of arbitrary cluster-scoped resources and privilege escalation to cluster-admin — a serious risk in shared Kubernetes management planes.
8
An authorization bypass in LXD permits an authenticated attacker to override project security restrictions during instance migration by supplying configuration overrides that are not validated against the target project's enforced policy — effectively allowing high-privilege instances to be smuggled into restricted projects.
9
A TOCTOU (time-of-check to time-of-use) race condition in LXD's configuration merging during cross-project instance copies allows an attacker to pass restriction checks before disallowed configuration is fully merged — exploitation can result in bypassing project-level security boundaries in containerized environments.
10
A third authorization bypass in LXD affects cross-project instance migrations when a target cluster member is specified — the destination node entirely skips project restriction checks, allowing an authenticated attacker to move instances with disallowed privilege configurations to any target project without enforcement.
Ransomware today
The direwolf group has recently claimed Chat Jurídico, a Brazilian legal services firm, as a victim — a sector that handles sensitive privileged communications and client data. Over the past 30 days, lockbit5 has been the most active group globally with 21 victims, including 21 in Brazil, followed by Section9 (6), Global Secret Group (4), thegentlemen (3), L Group (2), and ransomhouse (2).
Chat Jurídico BRdirewolf · Professional Services
lockbit5 21Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs
Several threat actors are currently tracked as active or recently updated in threat intelligence feeds, including linkc, Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, and apt73. While no confirmed victims are linked to these groups in the current window, their presence in tracking systems warrants monitoring — particularly Darkhotel and Equation, which have historically targeted high-value government and enterprise environments.
Brazil focus
Brazil is facing an intense ransomware campaign period, with recent victims spanning multiple critical sectors: Chat Jurídico (Professional Services, direwolf), uva.edu.br (Education, L Group), Alya Construtora (Manufacturing, ransomhouse), brdigital.net.br (Technology, L Group), Intranet Gov Brasil (Government & Defense, thegentlemen), PontoBR Sistemas (Technology, spacebears), cesmac.edu.br (Education, krybit), and eSysTech (Technology, Orova). The breadth of targeted sectors — from government infrastructure to education and legal services — signals that Brazilian organizations across industries must treat ransomware preparedness as an immediate operational priority.
Chat Jurídicodirewolf · Professional Services
uva.edu.brL Group · Education
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
Intranet Gov Brasilthegentlemen · Government & Defense
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Organizations running LXD should apply available patches immediately and restrict who can import or restore backup and image archives — untrusted archive handling represents the highest-risk attack surface. Joomla administrators with the Fabrik extension installed should upgrade to 4.6.8 or disable the extension until patching is confirmed.
Given the volume of critical disclosures published today — particularly in container orchestration and web extension layers — it is essential to validate whether your exposed attack surface includes any of the affected components before adversaries have the chance to weaponize these findings.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →