Daily briefing · August 18, 2026

Wave of CVSS 10.0 Flaws Hits Oracle, WordPress, and Embedded Devices on a Quiet Exploitation Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 18, 2026 registered no active exploitation or weaponized vulnerabilities, placing the day firmly in calm territory — but the sheer volume of maximum-severity disclosures demands attention from defenders. Ten critical flaws were published in a single day, spanning Oracle enterprise middleware, a popular WordPress plugin, embedded networking gear, and Mozilla Firefox, all scoring CVSS 9.9 or 10.0. No confirmed in-the-wild exploitation has been observed yet, but the attack surface exposed is significant and the window before weaponization can be narrow.

Today’s brief
  • No KEV entries or weaponized exploits recorded today — threat level is calm but the patch backlog is heavy.
  • Five CVSS 10.0 flaws published in one day across Oracle Hyperion, Oracle Internet Directory, WP Compress, TRENDnet, and Firefox.
  • CVE-2026-75784 (TRENDnet TEW-WLC100) already has a public proof-of-concept — elevation to weaponized status is a realistic near-term risk.
  • Brazil-focused ransomware activity remains intense, with TOTVS, VR Advogados, and Vermont XCenter among recent victims.
210
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-76008CVSS 10affects CF-N1-S
A stack-based buffer overflow in Comfast CF-N1-S 2.6.0.1's URI parameter parsing function allows unauthenticated remote attackers to potentially execute arbitrary code; embedded devices are notoriously slow to patch, making this a persistent risk in network perimeters.
2
CVE-2026-70921CVSS 10affects Oracle Hyperion Financial Management
Unauthenticated network access via TLS can fully compromise Oracle Hyperion Financial Management 11.2.25.0.000, with scope change potential affecting adjacent systems — a critical risk for finance and ERP environments relying on this platform.
3
CVE-2026-70880CVSS 10affects Oracle Hyperion Data Relationship Management
Oracle Hyperion Data Relationship Management is exposed to unauthenticated compromise over TCP, again with lateral scope-change impact; organizations managing master data or financial hierarchies should treat this as an immediate patching priority.
4
CVE-2026-61241CVSS 10affects Oracle Internet Directory
An unauthenticated attacker with LDAP network access can fully compromise Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0, threatening directory services that underpin authentication for entire Oracle Fusion Middleware deployments.
5
CVE-2026-73343CVSS 10affects WP Compress
WP Compress versions below 7.20.01 allow unauthenticated remote code execution, giving any internet-connected attacker full control of affected WordPress sites — organizations running this plugin should update immediately.
6
CVE-2026-75784CVSS 10PoCaffects TEW-WLC100
A public proof-of-concept already exists for this stack-based buffer overflow in TRENDnet TEW-WLC100's HTTP header handler, making it the highest near-term weaponization risk on today's list — wireless LAN controllers should be patched or isolated without delay.
7
CVE-2026-75874CVSS 10affects Firefox
A sandbox escape in Firefox's Remote Settings Client component (fixed in Firefox 154 and Thunderbird 154) allows attackers to break out of browser isolation — users and organizations must update both applications promptly given browsers' status as a primary attack vector.
8
CVE-2026-73930CVSS 9.9affects Helidon
Oracle Helidon 4.5.3's Imperative Web Server is vulnerable to unauthenticated HTTP-based compromise with scope change, meaning a breach can cascade beyond the Helidon instance itself into broader cloud-native or microservices architectures.
9
CVE-2026-71059CVSS 9.9affects Oracle BI Publisher
Oracle BI Publisher exposes a SOAP-accessible Web Service API to low-privileged attackers who can escalate impact to additional Oracle Analytics products, representing a serious risk for business intelligence and reporting infrastructure.
10
CVE-2026-70920CVSS 9.9affects Oracle Hyperion Financial Management
A low-privileged attacker with SQL network access can fully compromise Oracle Hyperion Financial Management with scope change potential, compounding the risk already posed by CVE-2026-70921 in the same product version.
Ransomware today

Ransomware operators continue to target Brazilian organizations at a notable pace. Recently, dragonforce claimed Vermont XCenter, direwolf listed TOTVS — one of Brazil's largest ERP and technology providers — and Barracuda claimed VR Advogados in the professional services sector. Among the most active groups over the last 30 days, Section9, thegentlemen, and Global Secret Group collectively account for the bulk of Brazilian victims, signaling sustained and coordinated pressure on the country's business and government sectors.

Vermont XCenter BRdragonforce
TOTVS BRdirewolf · Technology
VR Advogados BRBarracuda · Professional Services
Section9 6thegentlemen 5Global Secret Group 4direwolf 2L Group 2qilin 2
Active groups & APTs

Several threat actor identities are being tracked this cycle, including kazu, kelvinsecurity, krybit, lamashtu, linkc, and the Iran-linked blackshadow group. While no confirmed victims are currently attributed to these actors in the monitored period, their presence in threat intelligence feeds warrants continued monitoring, particularly for organizations in sectors historically targeted by Iranian state-affiliated groups such as government, finance, and critical infrastructure.

Brazil focus

Brazil's threat landscape remains active across multiple sectors. Beyond the high-profile TOTVS and Vermont XCenter incidents, thegentlemen has been linked to attacks on Megalaser Industria Metalurgica LTDA, Vector Two Technology, and Intranet Gov Brasil, while direwolf also claimed Chat Jurídico and m3rx targeted tecnoabi.com. The breadth of victims — spanning government, manufacturing, technology, and legal services — underscores that no sector should consider itself low-priority in the current environment.

Vermont XCenterdragonforce
VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
tecnoabi.comm3rx · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Vector Two Technologythegentlemen · Technology
Chat Jurídicodirewolf · Professional Services
Intranet Gov Brasilthegentlemen · Government & Defense
Today’s recommendation: Organizations should immediately prioritize patching CVE-2026-75784 given the existing public proof-of-concept, and apply Oracle's patches across Hyperion, Internet Directory, and BI Publisher products before exploitation activity begins; Firefox and Thunderbird updates to version 154 should be treated as an urgent endpoint action.
Even on a day with no confirmed active exploitation, the breadth of critical-severity disclosures is a strong reminder that validating your organization's actual exposure — not just its patch inventory — is the only reliable way to know whether today's calm reflects safety or undetected risk.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share