Daily briefing · August 16, 2026

WordPress Plugins and Scriban Lead a Calm Day With 12 Critical CVEs, No Active Exploitation

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 16, 2026 registers as a calm day from an exploitation standpoint — no CVEs were weaponized, none confirmed in active exploitation, and no VulnCheck pre-CISA alerts. Still, 12 critical vulnerabilities published today demand attention, spanning WordPress plugin chains, an unpatched IoT router with public proof-of-concept exploits, and multiple sandbox-bypass flaws in the Scriban templating engine.

Today’s brief
  • No active exploitation or weaponized exploits recorded today, but 12 critical CVEs were published and require prompt review.
  • WordPress ecosystem accounts for four critical flaws today, including arbitrary file upload, PHP object injection, and unauthenticated privilege escalation.
  • Edimax EW-7478APC router has two critical buffer overflow CVEs with public PoC code and a vendor that did not respond to disclosure — patch is unavailable.
  • Scriban templating engine carries three critical sandbox-bypass flaws; applications reusing TemplateContext instances across tenants are at direct risk.
12
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-16098CVSS 9.8affects ProSolution WP Client
The ProSolution WP Client plugin allows unauthenticated arbitrary file upload through a Content-Disposition header manipulation that bypasses the plugin's allowlist, enabling remote code execution on affected WordPress sites running version 2.0.10 or earlier.
2
CVE-2024-13784CVSS 9.8affects Contact Form, Survey, Quiz & Popup Form Builder – ARForms
ARForms plugin's deserialization of untrusted form input enables PHP Object Injection by unauthenticated attackers; while no known POP chain exists in the plugin itself, the risk escalates sharply if other vulnerable packages are present in the same environment.
3
CVE-2026-18432CVSS 9.8affects Frontend Admin by DynamiApps
Frontend Admin by DynamiApps contains a privilege escalation flaw where passing a non-numeric string as a user ID bypasses the authorization check entirely, allowing unauthenticated actors to elevate privileges on WordPress sites up to version 3.29.9.
4
CVE-2026-19961CVSS 9.4PoCaffects EW-7478APC
A public proof-of-concept exploit exists for this stack-based buffer overflow in the Edimax EW-7478APC router's formWlSiteSurvey function, triggerable remotely with no vendor patch available — IoT-exposed devices should be treated as unmitigable until an update is released.
5
CVE-2026-19959CVSS 9.4PoCaffects EW-7478APC
A second remotely exploitable buffer overflow in the same Edimax EW-7478APC firmware affects the formWanTcpipSetup function via the pppUserName argument; the exploit is public and the vendor has not responded, compounding the risk of the companion CVE-2026-19961.
6
CVE-2026-74790CVSS 9.3affects scriban
Scriban's TypedObjectAccessor caches type accessors without accounting for MemberFilter changes, meaning a reused TemplateContext can silently expose properties that a tightened filter was supposed to hide — a direct sandbox policy bypass in multi-tenant or multi-request deployments.
7
CVE-2026-73061CVSS 9.3affects scriban
A separate access-modifier bypass in Scriban allows template code to write to CLR object properties that have private, internal, or init-only setters, enabling mass assignment attacks that can permanently alter live host objects after rendering; all versions before 7.2.2 are affected.
8
CVE-2026-73056CVSS 9.3affects siyuan
SiYuan's CheckAuth() middleware accepts API tokens via header or query parameter with no brute-force protection — no CAPTCHA, no lockout — making kernel versions before 3.7.4 trivially vulnerable to credential stuffing against the API token.
9
CVE-2026-74251CVSS 9.3affects Phoca Cart extension for Joomla
Unauthenticated SQL injection in the Phoca Cart Joomla extension (versions 5.0.0 through 6.1.6) via raw concatenation of attribute and specification GET parameters enables full database exfiltration without any login, a severe risk for any public-facing e-commerce Joomla site.
10
CVE-2026-74791CVSS 9.2affects scriban
Scriban's TemplateContext.Reset() fails to clear the CachedTemplates dictionary, allowing previously authorized template content to leak into subsequent requests on reused contexts — exploitable in applications with request-dependent template loaders before version 7.0.0.
Ransomware today

Several Brazilian organizations have been claimed as ransomware victims in recent days, with TOTVS (Technology) hit by direwolf, VR Advogados (Professional Services) by Barracuda, tecnoabi.com and Vector Two Technology (both Technology) by m3rx and thegentlemen respectively, and Megalaser Industria Metalurgica LTDA (Manufacturing) also claimed by thegentlemen. Among the most active groups in the last 30 days, lockbit5 leads with 14 victims — all in Brazil — followed by Section9 (6), thegentlemen (5), and Global Secret Group (4), all with their entire known victim count concentrated in Brazilian targets.

TOTVS BRdirewolf · Technology
VR Advogados BRBarracuda · Professional Services
tecnoabi.com BRm3rx · Technology
Vector Two Technology BRthegentlemen · Technology
Megalaser Industria Metalurgica LTDA BRthegentlemen · Manufacturing
lockbit5 14Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2
Active groups & APTs

Several threat actor handles — including kazu, kelvinsecurity, krybit, lamashtu, and linkc — are being tracked with no confirmed victims reported yet, suggesting early-stage or reconnaissance activity. The Iranian group blackshadow is also flagged as active with no known victims at this time, though its historical profile warrants continued monitoring for targeted operations.

Brazil focus

Brazil is under sustained ransomware pressure, with at least eight organizations claimed across multiple sectors in recent weeks, including government (Intranet Gov Brasil, claimed by thegentlemen), legal services (VR Advogados, Chat Jurídico), manufacturing (Megalaser), and technology (TOTVS, Vector Two Technology, tecnoabi.com, brdigital.net.br). The concentration of attacks from groups like thegentlemen and direwolf specifically within Brazil indicates that local organizations are being actively selected as targets, not caught incidentally in global campaigns.

VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Vector Two Technologythegentlemen · Technology
tecnoabi.comm3rx · Technology
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
brdigital.net.brL Group · Technology
Today’s recommendation: Organizations running the affected WordPress plugins, Scriban, SiYuan, or Phoca Cart for Joomla should apply available patches immediately and audit plugin versions; for the Edimax EW-7478APC, consider network isolation or replacement given the absence of vendor response and the public availability of exploit code.
Even on a day with no confirmed active exploitation, the presence of public PoC code and multiple unauthenticated attack vectors underscores why validating your actual external and internal attack surface — rather than relying on patch timelines alone — is the only way to know whether today's quiet becomes tomorrow's incident.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share