Daily briefing · August 19, 2026
Six CVSS 10.0 Cisco Flaws and a WordPress Zero-Write Lead a Calm but Patch-Heavy August 19
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 19, 2026 brings no actively exploited vulnerabilities and no confirmed in-the-wild usage, keeping the day's verdict firmly calm — but the sheer volume of critical-severity disclosures demands attention from defenders. Six CVSS 10.0 findings across Cisco Secure Workload and Cisco Crosswork Planning, a file-overwrite flaw in W3 Total Cache with a proof of concept, and three critical Joomla extension bugs round out a day that requires methodical patching rather than emergency response. With 101 critical CVEs published out of 664 new entries, the patch backlog grows significantly even on a quiet day.
Today’s brief
- No active exploitation or KEV additions recorded on August 19 — but 101 critical CVEs were published, demanding triage
- Cisco discloses five CVSS 10.0 flaws across Secure Workload and Crosswork Planning, covering improper access control, authentication bypass, command injection, and file system manipulation
- W3 Total Cache (WordPress) has a proof-of-concept unauthenticated file-write flaw that can destroy .htaccess on Apache — patch before a PoC matures into a weapon
- Three Joomla extensions carry CVSS 10.0 bugs: arbitrary file upload in Zoo, path-traversal upload in J-BusinessDirectory, and pre-auth PHP code injection in Balbooa Forms
Critical highlights
1
An unauthenticated attacker can write or overwrite any file in any directory the web server can reach, including .htaccess on Apache — a proof of concept already exists, meaning the window before weaponization could be very short for the millions of sites running W3 Total Cache.
2
An abandoned auto-update domain in OZOLS creates a supply-chain-style attack surface: an adversary who seizes the domain can push unsigned code through the SQL Server Agent job and the OzolsSQL update channel, potentially achieving silent, persistent compromise of Windows-hosted database environments.
3
Improper access control in Cisco Secure Workload (CVSS 10.0) could allow an unauthenticated attacker to bypass authorization on the platform that orchestrates micro-segmentation policies — undermining the very tool meant to contain lateral movement.
4
An improper authentication flaw in Cisco Secure Workload at the same maximum severity score means an attacker may authenticate as a privileged entity without valid credentials, combining dangerously with CVE-2026-20315 if both remain unpatched.
5
Missing authentication for a critical function in Cisco Crosswork Planning exposes network orchestration logic to unauthenticated access, potentially allowing an attacker to manipulate or disrupt network planning operations at scale.
6
External control of the file system in Cisco Crosswork Planning means an unauthenticated actor could read, write, or delete files on the underlying host, turning a network management appliance into a beachhead for deeper infrastructure access.
7
Improper neutralization of special elements (command injection) in Cisco Crosswork Planning at CVSS 10.0 could allow unauthenticated remote code execution on the appliance — the most severe class of impact, and a priority patch target in any Cisco-heavy environment.
8
Path traversal in J-BusinessDirectory for Joomla lets a remote attacker upload or delete files outside the intended component directory, and the missing CSRF token compounds the risk by enabling drive-by exploitation through crafted links.
9
An unauthenticated file upload flaw in the Zoo Joomla extension accepts any file as long as its declared Content-Type is an image MIME type — a trivial bypass that could result in a webshell being dropped on any site running Zoo below 4.1.64.
10
Pre-authentication PHP code injection via eval() in Balbooa Forms for Joomla is one of the most immediately dangerous bugs in today's list: an unauthenticated remote attacker can execute arbitrary PHP code, leading directly to full server compromise on unpatched instances.
Ransomware today
Two Brazilian victims have surfaced recently: the Prefeitura Municipal de Arcos, a municipal government, was claimed by the grupo emperador, while Vermont XCenter was listed by DragonForce. Among the most active groups over the past 30 days, Section9 leads with six victims — all in Brazil — followed by thegentlemen with five Brazilian victims and Global Secret Group with four, signaling a sustained focus on Brazilian targets across government, technology, and professional services sectors.
Prefeitura Municipal de Arcos BRemperador · Government & Defense
Vermont XCenter BRdragonforce
Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2emperador 1
Active groups & APTs
Several threat actor identifiers have been flagged as active or updated, including kazu, kelvinsecurity, krybit, lamashtu, linkc, and Iran-linked blackshadow — none with confirmed victims in this cycle but all worth monitoring for infrastructure or tooling updates that may precede new campaigns.
Brazil focus
Brazil continues to face intense ransomware pressure across multiple sectors in recent weeks: TOTVS (Technology) was hit by direwolf, VR Advogados (Professional Services) by Barracuda, tecnoabi.com and Vector Two Technology by m3rx and thegentlemen respectively, Megalaser Industria Metalurgica by thegentlemen, and Chat Jurídico by direwolf — a pattern that shows no single vertical is being spared and that groups like thegentlemen and direwolf have made Brazil a primary operational focus.
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
Today’s recommendation: Organizations running Cisco Secure Workload, Cisco Crosswork Planning, W3 Total Cache, or any of the affected Joomla extensions should apply vendor patches immediately, prioritizing internet-facing or network-orchestration systems given the CVSS 10.0 ratings and, in the case of W3 Total Cache, the already-public proof of concept. Treat Balbooa Forms as an emergency given the pre-auth code execution primitive.
Even on a calm day with no confirmed active exploitation, the breadth of critical-severity disclosures is a strong reminder to validate which of these components are present in your environment before a quiet day turns into an incident.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →