Daily briefing · August 19, 2026

Six CVSS 10.0 Cisco Flaws and a WordPress Zero-Write Lead a Calm but Patch-Heavy August 19

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 19, 2026 brings no actively exploited vulnerabilities and no confirmed in-the-wild usage, keeping the day's verdict firmly calm — but the sheer volume of critical-severity disclosures demands attention from defenders. Six CVSS 10.0 findings across Cisco Secure Workload and Cisco Crosswork Planning, a file-overwrite flaw in W3 Total Cache with a proof of concept, and three critical Joomla extension bugs round out a day that requires methodical patching rather than emergency response. With 101 critical CVEs published out of 664 new entries, the patch backlog grows significantly even on a quiet day.

Today’s brief
  • No active exploitation or KEV additions recorded on August 19 — but 101 critical CVEs were published, demanding triage
  • Cisco discloses five CVSS 10.0 flaws across Secure Workload and Crosswork Planning, covering improper access control, authentication bypass, command injection, and file system manipulation
  • W3 Total Cache (WordPress) has a proof-of-concept unauthenticated file-write flaw that can destroy .htaccess on Apache — patch before a PoC matures into a weapon
  • Three Joomla extensions carry CVSS 10.0 bugs: arbitrary file upload in Zoo, path-traversal upload in J-BusinessDirectory, and pre-auth PHP code injection in Balbooa Forms
101
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-18051CVSS 10PoCaffects W3 Total Cache
An unauthenticated attacker can write or overwrite any file in any directory the web server can reach, including .htaccess on Apache — a proof of concept already exists, meaning the window before weaponization could be very short for the millions of sites running W3 Total Cache.
2
CVE-2026-22306CVSS 10affects OZOLS
An abandoned auto-update domain in OZOLS creates a supply-chain-style attack surface: an adversary who seizes the domain can push unsigned code through the SQL Server Agent job and the OzolsSQL update channel, potentially achieving silent, persistent compromise of Windows-hosted database environments.
3
CVE-2026-20315CVSS 10affects Cisco Secure Workload
Improper access control in Cisco Secure Workload (CVSS 10.0) could allow an unauthenticated attacker to bypass authorization on the platform that orchestrates micro-segmentation policies — undermining the very tool meant to contain lateral movement.
4
CVE-2026-20317CVSS 10affects Cisco Secure Workload
An improper authentication flaw in Cisco Secure Workload at the same maximum severity score means an attacker may authenticate as a privileged entity without valid credentials, combining dangerously with CVE-2026-20315 if both remain unpatched.
5
CVE-2026-20357CVSS 10affects Cisco Crosswork Planning
Missing authentication for a critical function in Cisco Crosswork Planning exposes network orchestration logic to unauthenticated access, potentially allowing an attacker to manipulate or disrupt network planning operations at scale.
6
CVE-2026-20358CVSS 10affects Cisco Crosswork Planning
External control of the file system in Cisco Crosswork Planning means an unauthenticated actor could read, write, or delete files on the underlying host, turning a network management appliance into a beachhead for deeper infrastructure access.
7
CVE-2026-20030CVSS 10affects Cisco Crosswork Planning
Improper neutralization of special elements (command injection) in Cisco Crosswork Planning at CVSS 10.0 could allow unauthenticated remote code execution on the appliance — the most severe class of impact, and a priority patch target in any Cisco-heavy environment.
8
CVE-2026-75949CVSS 10affects J-BusinessDirectory extension for Joomla
Path traversal in J-BusinessDirectory for Joomla lets a remote attacker upload or delete files outside the intended component directory, and the missing CSRF token compounds the risk by enabling drive-by exploitation through crafted links.
9
CVE-2026-74803CVSS 10affects Zoo extension for Joomla
An unauthenticated file upload flaw in the Zoo Joomla extension accepts any file as long as its declared Content-Type is an image MIME type — a trivial bypass that could result in a webshell being dropped on any site running Zoo below 4.1.64.
10
CVE-2026-67364CVSS 10affects Balbooa Forms extension for Joomla
Pre-authentication PHP code injection via eval() in Balbooa Forms for Joomla is one of the most immediately dangerous bugs in today's list: an unauthenticated remote attacker can execute arbitrary PHP code, leading directly to full server compromise on unpatched instances.
Ransomware today

Two Brazilian victims have surfaced recently: the Prefeitura Municipal de Arcos, a municipal government, was claimed by the grupo emperador, while Vermont XCenter was listed by DragonForce. Among the most active groups over the past 30 days, Section9 leads with six victims — all in Brazil — followed by thegentlemen with five Brazilian victims and Global Secret Group with four, signaling a sustained focus on Brazilian targets across government, technology, and professional services sectors.

Prefeitura Municipal de Arcos BRemperador · Government & Defense
Vermont XCenter BRdragonforce
Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2emperador 1
Active groups & APTs

Several threat actor identifiers have been flagged as active or updated, including kazu, kelvinsecurity, krybit, lamashtu, linkc, and Iran-linked blackshadow — none with confirmed victims in this cycle but all worth monitoring for infrastructure or tooling updates that may precede new campaigns.

Brazil focus

Brazil continues to face intense ransomware pressure across multiple sectors in recent weeks: TOTVS (Technology) was hit by direwolf, VR Advogados (Professional Services) by Barracuda, tecnoabi.com and Vector Two Technology by m3rx and thegentlemen respectively, Megalaser Industria Metalurgica by thegentlemen, and Chat Jurídico by direwolf — a pattern that shows no single vertical is being spared and that groups like thegentlemen and direwolf have made Brazil a primary operational focus.

Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
Today’s recommendation: Organizations running Cisco Secure Workload, Cisco Crosswork Planning, W3 Total Cache, or any of the affected Joomla extensions should apply vendor patches immediately, prioritizing internet-facing or network-orchestration systems given the CVSS 10.0 ratings and, in the case of W3 Total Cache, the already-public proof of concept. Treat Balbooa Forms as an emergency given the pre-auth code execution primitive.
Even on a calm day with no confirmed active exploitation, the breadth of critical-severity disclosures is a strong reminder to validate which of these components are present in your environment before a quiet day turns into an incident.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share