Daily briefing · August 22, 2026

Joomla's Fabrik Extension Dominates a Quiet Day with Four CVSS 10.0 Flaws

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 22, 2026 was a calm day on the vulnerability front, with zero active exploitation confirmed and no weaponized exploits observed. Despite the low threat tempo, the day's highlights are far from trivial: four simultaneous CVSS 10.0 vulnerabilities in the Fabrik extension for Joomla demand immediate attention from any team running that plugin. No KEV entries were added and no VulnCheck early-warning signals were triggered, but the sheer severity of the Fabrik cluster warrants urgent patching action.

Today’s brief
  • Four CVSS 10.0 flaws in Joomla's Fabrik extension, including unauthenticated RCE and path traversal — patch to 4.7.3 immediately.
  • TRENDnet TEW-821DAP and Comfast CF-N1-S each carry CVSS 10.0/9.4 stack-based buffer overflow flaws with proof-of-concept code available.
  • WordPress plugins Mailgun and WS Form LITE carry critical unauthenticated SSRF and PHP Object Injection risks respectively.
  • Brazil continues to be a ransomware hotspot: thegentlemen, dragonforce, direwolf and others have targeted Brazilian organizations across multiple sectors recently.
13
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-76606CVSS 10affects Fabrik extension for Joomla
A path traversal vulnerability via the image element in Fabrik for Joomla (versions below 4.7.3) scores a perfect CVSS 10.0, meaning an attacker could navigate the server's filesystem without authentication — a serious risk for any publicly accessible Joomla site running this extension.
2
CVE-2026-76605CVSS 10affects Fabrik extension for Joomla
Remote code execution via the image element in Fabrik below 4.7.3, also rated CVSS 10.0; combined with CVE-2026-76606, attackers could traverse directories and then execute arbitrary code, making this pairing especially dangerous in shared hosting environments.
3
CVE-2026-76604CVSS 10affects Fabrik extension for Joomla
Unauthenticated remote code execution through Fabrik's PHP form element (below 4.7.3) is perhaps the most directly exploitable of the cluster: any visitor can submit user-controlled PHP code that the server executes, requiring no credentials or prior access whatsoever.
4
CVE-2026-76607CVSS 10affects Fabrik extension for Joomla
A missing ACL check in Fabrik's download element (below 4.7.3) allows unauthorized file downloads, rounding out a four-CVE cluster that collectively gives an unauthenticated attacker read, write, execute, and exfiltration capabilities on affected Joomla installations.
5
CVE-2026-77946CVSS 10PoCaffects TEW-821DAP
A stack-based buffer overflow in the TRENDnet TEW-821DAP (firmware 2.2.01b05) NTP Timezone Configuration Handler can be triggered remotely by manipulating NTP-related arguments, with a proof of concept available — IoT/network device administrators should prioritize firmware review.
6
CVE-2026-78003CVSS 9.8affects Mailgun for WordPress
The Mailgun for WordPress plugin (up to version 2.2.0) is vulnerable to SSRF via path traversal in its add_list() function, exploitable by unauthenticated attackers; this could allow internal network probing or access to cloud metadata endpoints from the WordPress server.
7
CVE-2026-4703CVSS 9.8affects WS Form LITE – Drag & Drop Contact Form Builder
PHP Object Injection via deserialization of untrusted form submission data in WS Form LITE (up to 1.10.80) can be triggered by unauthenticated users; while no known POP chain currently exists in the plugin itself, a single vulnerable dependency in the environment could turn this into full remote code execution.
8
CVE-2026-77992CVSS 9.5affects Fabrik extension for Joomla
A heredoc terminator breakout in Fabrik's calc element (below 4.7.2), combined with an endpoint that performs no access checks, could allow attackers to inject and execute server-side logic — yet another vector in the Fabrik cluster that reinforces the urgency of upgrading past 4.7.3.
9
CVE-2026-78050CVSS 9.4PoCaffects CF-N1-S
A remotely exploitable stack-based buffer overflow in the Comfast CF-N1-S 2.6.0.1 web management interface (NTP timezone handler) has a public exploit; organizations using this device on their network edge should isolate or replace it pending a vendor patch.
10
CVE-2026-12710CVSS 9.3affects Application Integration
A missing authorization flaw in Google Cloud Application Integration's QueryEngineTask allowed external attackers to access sensitive internal data; Google patched this on April 4, 2026, and no customer action is required — but teams should confirm their environment is on a post-patch version and audit recent API access logs as a precaution.
Ransomware today

Ransomware activity against Brazilian targets remains notably high: recently, thegentlemen claimed UOLconsult (Professional Services) as a victim, while emperador targeted Prefeitura Municipal de Arcos, a Brazilian municipal government. Thegentlemen leads the 30-day ranking with six confirmed victims — all in Brazil — followed by Section9 also with six Brazilian victims, underscoring a concentrated and sustained campaign against the country.

UOLconsult BRthegentlemen · Professional Services
Prefeitura Municipal de Arcos BRemperador · Government & Defense
thegentlemen 6Section9 6Global Secret Group 4L Group 2direwolf 2emperador 1
Active groups & APTs

Several threat actor identifiers — including kazu, kelvinsecurity, krybit, lamashtu, linkc, and the Iranian-linked group blackshadow — are currently being tracked with no publicly confirmed victims at this time. Blackshadow's Iranian origin warrants attention given that group's historical focus on data destruction and espionage; defenders in sectors historically targeted by Iranian actors should maintain heightened monitoring even in the absence of confirmed recent activity.

Brazil focus

Brazil is facing a sustained ransomware wave across multiple sectors: recent victims include UOLconsult and VR Advogados (Professional Services), Prefeitura Municipal de Arcos (Government & Defense), TOTVS and tecnoabi.com (Technology), Vermont XCenter, Megalaser Industria Metalurgica LTDA (Manufacturing), and Vector Two Technology. Groups such as thegentlemen, dragonforce, direwolf, Barracuda, m3rx, and emperador have all been linked to Brazilian victims in the past 30 days, reflecting a broad and opportunistic targeting pattern across the Brazilian economy.

UOLconsultthegentlemen · Professional Services
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Today’s recommendation: Organizations running the Fabrik extension for Joomla should upgrade to version 4.7.3 or later immediately, as all four critical CVEs are resolved in that release; simultaneously, audit WordPress plugins Mailgun and WS Form LITE for pending updates and review network device firmware for TRENDnet and Comfast appliances.
Even on a quieter CVE day, the breadth of critical flaws across web platforms and network devices is a reminder that validating your own attack surface — not just tracking published advisories — is the only way to know if your environment is truly exposed.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share