Daily briefing · August 14, 2026

Quiet Day, High Stakes: Ten Critical CVEs Published Across AI, ICS, IBM and WordPress

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 14, 2026 brought no active exploitation or weaponized exploits, but the day's publication record is far from trivial — 201 new CVEs emerged, including 28 critical-severity entries. The standout concerns are a pair of CVSS 10.0 remote code execution flaws, multiple IBM Db2 Mirror for i weaknesses, and a cluster of WordPress authentication-bypass vulnerabilities, all published today and awaiting attacker attention.

Today’s brief
  • Two CVSS 10.0 unauthenticated RCE flaws disclosed today: one in MindsDB Minds Platform, one in Haiwell IoT Cloud HMI Gateway — both reachable without credentials
  • IBM Db2 Mirror for i (versions 7.4–7.6) hit with three critical CVEs: arbitrary CL command execution, path traversal code execution, and authentication bypass
  • WordPress ecosystem takes heavy hits: Wishlist Member, User Session Synchronizer, and 6Storage Rentals all expose full account takeover to unauthenticated attackers
  • No active exploitation confirmed today, but the volume and severity of new disclosures demand immediate patch prioritization
28
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-73678CVSS 10affects Minds Platform
A CVSS 10.0 unauthenticated RCE in MindsDB Minds Platform (v26.1.0 and earlier) allows any attacker to execute arbitrary OS commands by sending crafted prompts to an unprotected API endpoint that calls exec() on attacker-controlled Python code with no sandboxing — a critical exposure for any organization running this AI platform publicly.
2
CVE-2026-19188CVSS 10affects Haiwell IoT Cloud HMI Gateway
A CVSS 10.0 OS command injection in the Haiwell IoT Cloud HMI Gateway's Net Check feature allows unauthenticated attackers to inject arbitrary commands via a Socket.io event — ICS/OT environments running this device should treat this as an emergency priority given the lack of input sanitization.
3
CVE-2026-17186CVSS 9.9affects Db2 Mirror for i
IBM Db2 Mirror for i (7.4, 7.5, 7.6) allows remote attackers to execute arbitrary CL commands due to improper neutralization of special elements — a CVSS 9.9 flaw that could result in full system compromise on affected IBM i environments.
4
CVE-2026-72811CVSS 9.9affects siyuan
SiYuan (v3.7.2 and earlier) carries a first-order SQL injection in its backlink/mention search that allows stored metadata to break out of SQL context when combined with a client-supplied single quote — defenders running this note-taking platform internally should patch immediately to prevent data exfiltration or privilege escalation.
5
CVE-2026-12949CVSS 9.8affects Wishlist Member
The Wishlist Member WordPress plugin (up to v3.34.1) enables full account takeover through insufficient verification of registration parameters, allowing an unauthenticated attacker to merge into arbitrary user accounts — sites using this membership plugin should disable or update without delay.
6
CVE-2026-15341CVSS 9.8affects User Session Synchronizer
User Session Synchronizer for WordPress (up to v1.4.0) performs zero validation on attacker-supplied session synchronization parameters, firing on every request and allowing complete authentication bypass and account takeover — any site with this plugin installed is effectively open to unauthenticated admin access.
7
CVE-2026-15303CVSS 9.8affects 6Storage Rentals
The 6Storage Rentals WordPress plugin (up to v2.27.0) exposes an AJAX handler with no nonce, capability, or ownership checks, letting unauthenticated attackers set session cookies for any existing WordPress user — this is a trivially exploitable authentication bypass requiring immediate remediation.
8
CVE-2026-17184CVSS 9.8affects Db2 Mirror for i
IBM Db2 Mirror for i (7.4, 7.5, 7.6) is vulnerable to arbitrary code execution via external control of file name or path — when chained with other weaknesses in the same product cluster, this raises the overall risk posture for IBM i shops significantly.
9
CVE-2026-17182CVSS 9.8affects Db2 Mirror for i
A third critical flaw in IBM Db2 Mirror for i allows remote attackers to bypass authentication and read or modify sensitive data through improper validation of URI path segments — organizations relying on this platform for database mirroring should apply IBM's guidance as an urgent priority.
10
CVE-2026-50027CVSS 9.8affects mcp-memory-service
The mcp-memory-service AI memory layer (prior to v10.67.1) exposes all document API routes without authentication even when an API key or OAuth is configured — unauthenticated attackers can upload, retrieve, or manipulate the entire memory store, posing a serious data integrity and confidentiality risk for AI-driven applications.
Ransomware today

Ransomware activity targeting Brazil remains notably intense in recent days. The groups thegentlemen and m3rx claimed new Brazilian victims, including Vector Two Technology and Megalaser Industria Metalurgica LTDA (thegentlemen) and tecnoabi.com (m3rx). Over the past 30 days, lockbit5 leads all groups in activity with 21 confirmed victims, all in Brazil, underlining the country's continued status as a primary ransomware target.

tecnoabi.com BRm3rx · Technology
Vector Two Technology BRthegentlemen · Technology
Megalaser Industria Metalurgica LTDA BRthegentlemen · Manufacturing
lockbit5 21Section9 6thegentlemen 5Global Secret Group 4L Group 2ransomhouse 2
Active groups & APTs

Several threat actor clusters are being monitored for potential activity, including linkc, Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, and apt73. No new confirmed victims have been attributed to these groups in the current window, but their continued tracking reflects ongoing intelligence interest in their infrastructure and targeting patterns.

Brazil focus

Brazil's threat landscape remains highly active across multiple sectors in recent weeks. Confirmed ransomware victims include tecnoabi.com and Vector Two Technology (Technology), Megalaser Industria Metalurgica LTDA (Manufacturing), Chat Jurídico (Professional Services), uva.edu.br (Education), Intranet Gov Brasil (Government & Defense), brdigital.net.br (Technology), and Alya Construtora (Manufacturing) — with groups including thegentlemen, m3rx, direwolf, L Group, and ransomhouse all demonstrating a clear, sustained focus on Brazilian targets across both public and private sectors.

tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
uva.edu.brL Group · Education
Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Alya Construtoraransomhouse · Manufacturing
Today’s recommendation: Security teams should prioritize patching today's CVSS 10.0 RCE flaws in MindsDB and Haiwell before exploitation attempts begin, while immediately auditing WordPress deployments for the three authentication-bypass plugins and applying IBM's mitigations for the Db2 Mirror for i cluster.
Knowing which of today's critical vulnerabilities exist in your environment is the first step — validating that your controls actually prevent their exploitation is what separates monitoring from real resilience.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share