Daily briefing · August 17, 2026
Quiet Vulnerability Day Masks Active Ransomware Pressure on Brazil
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 17, 2026 registers as a calm day on the exploitation front — no CVEs confirmed in active exploitation, no weaponized modules, and no VulnCheck early-warning signals — but the 42 critical vulnerabilities published demand attention. Meanwhile, ransomware groups continue hitting Brazilian targets at a notable pace, underscoring that the threat landscape rarely stands still even when the CVE feed appears orderly.
Today’s brief
- No CVEs confirmed in active exploitation today, but 42 critical issues were published — patch queues remain non-trivial
- Two vm2 sandbox-escape flaws (CVE-2026-47686, CVE-2026-47698) pose severe risk to any Node.js environment relying on vm2 for isolation
- ERPNext SSTI (CVE-2026-65974) and Joomla Sourcerer RCE (CVE-2026-74253) threaten open-source ERP and CMS deployments worldwide
- Brazil faces concentrated ransomware activity: six new victims disclosed recently, with dragonforce, thegentlemen, and direwolf leading attacks
Critical highlights
1
A CVSS 10.0 authentication bypass in the session validation logic of ipTIME A3004T routers is now public with a working proof of concept, enabling unauthenticated remote access — any exposed management interface should be considered compromised until patched.
2
Unauthenticated remote code execution in the Sourcerer extension for Joomla (versions before 14.0.0) arises from unverified reflected user input processed in final rendered HTML, making any public-facing Joomla site with this extension a high-priority patching target.
3
A stack-based buffer overflow via the HTTP_COOKIE argument in Wavlink WN531P3 and WN535M1 routers, with a public proof of concept, allows remote attackers to execute arbitrary code — consumer and SOHO networking gear remains a persistent weak point in perimeter defenses.
4
A sandbox escape in vm2 prior to 3.11.6 lets malicious code reach the host process object through an unsanitized Error.cause property in handleException(), completely defeating the isolation guarantee that vm2 is designed to provide.
5
A server-side template injection vulnerability in ERPNext (fixed in 15.111.0 and 16.22.0) allows limited authenticated users to execute arbitrary code by exploiting an exposed frappe.render_template call without restricted globals — ERP systems holding sensitive business data are a high-value target.
6
A privilege escalation flaw in the multicloud-operators-subscription component of Red Hat Multicluster Global Hub allows a managed-cluster user to deploy resources into any namespace with the controller's elevated Service Account permissions, effectively enabling cluster-wide compromise from a low-privilege position.
7
A second critical vm2 sandbox escape (CVSS 9.8), fixed in 3.11.6, exploits stacked indirection through Function.prototype.call to reach arbitrary host command execution — organizations running any version of vm2 below 3.11.6 should treat both this and CVE-2026-47686 as a combined emergency update.
8
A token leakage flaw in the Onyx AI platform exposes one user's OAuth Authorization headers to other users through a shared admin configuration row, creating a serious cross-tenant credential theft risk in any multi-user Onyx deployment before versions 3.1.10, 3.2.14, or 4.0.0.
9
A blind SQL injection in a legacy dashboard widget API of Google SecOps (Chronicle SOAR) before version 6.3.85 can be exploited by an authenticated attacker to extract sensitive data; Google has patched this server-side and no customer action is required, but it is a reminder that even managed security platforms carry software risk.
10
An OS command injection via the ssid parameter in the CGI interface of COMFAST CF-N1-S 2.6.0.1, backed by a public proof of concept, allows remote unauthenticated command execution — wireless infrastructure devices with exposed CGI interfaces continue to be low-hanging fruit for attackers.
Ransomware today
Six Brazilian organizations have been listed as ransomware victims in recent disclosures, spanning multiple sectors: Vermont XCenter and TOTVS (Technology, hit by dragonforce and direwolf respectively), VR Advogados (Professional Services, Barracuda), tecnoabi.com (Technology, m3rx), and Vector Two Technology alongside Megalaser Industria Metalurgica LTDA (both claimed by thegentlemen). Among the most active groups over the past 30 days, lockbit5, Section9, and thegentlemen lead in volume, with a striking concentration of attacks directed specifically at Brazilian targets.
Vermont XCenter BRdragonforce
TOTVS BRdirewolf · Technology
VR Advogados BRBarracuda · Professional Services
tecnoabi.com BRm3rx · Technology
Vector Two Technology BRthegentlemen · Technology
Megalaser Industria Metalurgica LTDA BRthegentlemen · Manufacturing
lockbit5 8Section9 6thegentlemen 5Global Secret Group 4direwolf 2L Group 2
Active groups & APTs
Several threat actor handles — including kazu, kelvinsecurity, krybit, lamashtu, linkc, and the Iranian-linked group blackshadow — appear in current tracking with no confirmed victims yet attributed to them. While the absence of confirmed victims may reflect limited visibility rather than inactivity, the presence of blackshadow, historically associated with disruptive operations out of Iran, warrants continued monitoring for any escalation in the near term.
Brazil focus
Brazil is facing sustained and broad ransomware pressure, with recent victims spanning technology firms (TOTVS, tecnoabi.com, Vector Two Technology), professional services (VR Advogados, Chat Jurídico), manufacturing (Megalaser Industria Metalurgica LTDA), and even government infrastructure (Intranet Gov Brasil, claimed by thegentlemen). The diversity of sectors and the concentration of leading ransomware groups — lockbit5, Section9, thegentlemen, and direwolf — operating almost exclusively within Brazil during the past 30 days signals an elevated and persistent threat environment for Brazilian organizations of all sizes.
Vermont XCenterdragonforce
VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
tecnoabi.comm3rx · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Vector Two Technologythegentlemen · Technology
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Today’s recommendation: Prioritize emergency patching of vm2 to version 3.11.6 to address both sandbox escapes (CVE-2026-47686 and CVE-2026-47698), update ERPNext and Joomla Sourcerer to their latest releases, and audit exposed CGI and router management interfaces for the Wavlink and COMFAST flaws — all backed by public proof-of-concept code.
Even on a calm exploitation day, the presence of 42 critical CVEs and active ransomware campaigns is a strong prompt to map which of these products and components exist in your environment and validate whether your current controls would actually stop lateral movement if one of them were exploited.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →