Daily briefing · August 18, 2026
Wave of CVSS 10.0 Flaws Hits Oracle, WordPress, and Embedded Devices on a Quiet Exploitation Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 18, 2026 registered no active exploitation or weaponized vulnerabilities, placing the day firmly in calm territory — but the sheer volume of maximum-severity disclosures demands attention from defenders. Ten critical flaws were published in a single day, spanning Oracle enterprise middleware, a popular WordPress plugin, embedded networking gear, and Mozilla Firefox, all scoring CVSS 9.9 or 10.0. No confirmed in-the-wild exploitation has been observed yet, but the attack surface exposed is significant and the window before weaponization can be narrow.
Today’s brief
- No KEV entries or weaponized exploits recorded today — threat level is calm but the patch backlog is heavy.
- Five CVSS 10.0 flaws published in one day across Oracle Hyperion, Oracle Internet Directory, WP Compress, TRENDnet, and Firefox.
- CVE-2026-75784 (TRENDnet TEW-WLC100) already has a public proof-of-concept — elevation to weaponized status is a realistic near-term risk.
- Brazil-focused ransomware activity remains intense, with TOTVS, VR Advogados, and Vermont XCenter among recent victims.
Critical highlights
1
A stack-based buffer overflow in Comfast CF-N1-S 2.6.0.1's URI parameter parsing function allows unauthenticated remote attackers to potentially execute arbitrary code; embedded devices are notoriously slow to patch, making this a persistent risk in network perimeters.
2
Unauthenticated network access via TLS can fully compromise Oracle Hyperion Financial Management 11.2.25.0.000, with scope change potential affecting adjacent systems — a critical risk for finance and ERP environments relying on this platform.
3
CVE-2026-70880CVSS 10affects Oracle Hyperion Data Relationship Management Oracle Hyperion Data Relationship Management is exposed to unauthenticated compromise over TCP, again with lateral scope-change impact; organizations managing master data or financial hierarchies should treat this as an immediate patching priority.
4
An unauthenticated attacker with LDAP network access can fully compromise Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0, threatening directory services that underpin authentication for entire Oracle Fusion Middleware deployments.
5
WP Compress versions below 7.20.01 allow unauthenticated remote code execution, giving any internet-connected attacker full control of affected WordPress sites — organizations running this plugin should update immediately.
6
A public proof-of-concept already exists for this stack-based buffer overflow in TRENDnet TEW-WLC100's HTTP header handler, making it the highest near-term weaponization risk on today's list — wireless LAN controllers should be patched or isolated without delay.
7
A sandbox escape in Firefox's Remote Settings Client component (fixed in Firefox 154 and Thunderbird 154) allows attackers to break out of browser isolation — users and organizations must update both applications promptly given browsers' status as a primary attack vector.
8
Oracle Helidon 4.5.3's Imperative Web Server is vulnerable to unauthenticated HTTP-based compromise with scope change, meaning a breach can cascade beyond the Helidon instance itself into broader cloud-native or microservices architectures.
9
Oracle BI Publisher exposes a SOAP-accessible Web Service API to low-privileged attackers who can escalate impact to additional Oracle Analytics products, representing a serious risk for business intelligence and reporting infrastructure.
10
A low-privileged attacker with SQL network access can fully compromise Oracle Hyperion Financial Management with scope change potential, compounding the risk already posed by CVE-2026-70921 in the same product version.
Ransomware today
Ransomware operators continue to target Brazilian organizations at a notable pace. Recently, dragonforce claimed Vermont XCenter, direwolf listed TOTVS — one of Brazil's largest ERP and technology providers — and Barracuda claimed VR Advogados in the professional services sector. Among the most active groups over the last 30 days, Section9, thegentlemen, and Global Secret Group collectively account for the bulk of Brazilian victims, signaling sustained and coordinated pressure on the country's business and government sectors.
Vermont XCenter BRdragonforce
TOTVS BRdirewolf · Technology
VR Advogados BRBarracuda · Professional Services
Section9 6thegentlemen 5Global Secret Group 4direwolf 2L Group 2qilin 2
Active groups & APTs
Several threat actor identities are being tracked this cycle, including kazu, kelvinsecurity, krybit, lamashtu, linkc, and the Iran-linked blackshadow group. While no confirmed victims are currently attributed to these actors in the monitored period, their presence in threat intelligence feeds warrants continued monitoring, particularly for organizations in sectors historically targeted by Iranian state-affiliated groups such as government, finance, and critical infrastructure.
Brazil focus
Brazil's threat landscape remains active across multiple sectors. Beyond the high-profile TOTVS and Vermont XCenter incidents, thegentlemen has been linked to attacks on Megalaser Industria Metalurgica LTDA, Vector Two Technology, and Intranet Gov Brasil, while direwolf also claimed Chat Jurídico and m3rx targeted tecnoabi.com. The breadth of victims — spanning government, manufacturing, technology, and legal services — underscores that no sector should consider itself low-priority in the current environment.
Vermont XCenterdragonforce
VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
tecnoabi.comm3rx · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Vector Two Technologythegentlemen · Technology
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Today’s recommendation: Organizations should immediately prioritize patching CVE-2026-75784 given the existing public proof-of-concept, and apply Oracle's patches across Hyperion, Internet Directory, and BI Publisher products before exploitation activity begins; Firefox and Thunderbird updates to version 154 should be treated as an urgent endpoint action.
Even on a day with no confirmed active exploitation, the breadth of critical-severity disclosures is a strong reminder that validating your organization's actual exposure — not just its patch inventory — is the only reliable way to know whether today's calm reflects safety or undetected risk.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →