Daily briefing · August 23, 2026

Calm Day Masks Persistent Threats: Critical Authentication Bypass and Privilege Escalation Flaws Headline August 23

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

August 23 registers as a calm day with no vulnerabilities in active exploitation and no confirmed weaponized exploits, yet eight critical-severity CVEs demand attention — several with public proof-of-concept code already available. The day's highlights span improper authentication in network hardware, privilege escalation in Kubernetes operators, stack-based buffer overflows, and multiple sanitization bypass issues in widely-used libraries. Defenders should treat the absence of confirmed exploitation not as a green light, but as a shrinking window to patch before threat actors act.

Today’s brief
  • No active exploitation (KEV) recorded on August 23, but 8 critical CVEs were published — several with public PoC
  • Authentication bypass flaws in ipTIME network switches (CVSS 10.0 and 9.3) and buffer overflows in UTT HiPER routers carry remote exploitation risk
  • StackGres operator privilege escalation (CVSS 9.9) allows low-privilege tenants to gain full admin access — high-impact for Kubernetes environments
  • Brazilian healthcare sector targeted by ransomware group kazu; thegentlemen hit UOLconsult — ransomware pressure on BR remains elevated
8
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-78167CVSS 10PoCaffects ipTIME T16000M
A CVSS 10.0 improper authentication flaw in the EFM ipTIME T16000M Session Validation Handler is fully remotely exploitable, with a public exploit already available — any unauthenticated attacker can bypass session controls on this enterprise-grade switch, making immediate isolation or firmware update the only safe options.
2
CVE-2026-78155CVSS 9.9affects StackGres
A privilege escalation vulnerability in the StackGres Kubernetes operator allows a low-privilege database tenant to elevate to administrator — environments running multi-tenant StackGres deployments should treat this as an urgent patch, as database tenants commonly represent semi-trusted or externally-facing accounts.
3
CVE-2026-78169CVSS 9.4PoCaffects HiPER 1250GW
A stack-based buffer overflow in the UTT HiPER 1250GW HTTP Request Handler is remotely exploitable via a crafted Profile argument, with a public exploit now circulating — this class of flaw typically enables arbitrary code execution or device takeover on embedded network appliances.
4
CVE-2026-78168CVSS 9.3PoCaffects ipTIME T24000M
Mirroring CVE-2026-78167, the EFM ipTIME T24000M carries the same improper authentication weakness in its session validation logic with a public exploit available and no vendor response on record — exposure of management interfaces to untrusted networks represents a direct compromise risk.
5
CVE-2026-78207CVSS 9.3affects exceljs
A prototype pollution vulnerability in exceljs-hardened's deepMerge helper allows attackers to corrupt Object.prototype by injecting malicious keys through crafted cell note JSON — applications processing untrusted Excel files are at risk of logic subversion or remote code execution depending on downstream usage.
6
CVE-2026-8445CVSS 9.3affects justhtml
justhtml versions up to 1.11.0 fail to escape angle brackets in text nodes during Markdown conversion, meaning attacker-controlled input that appears safe in HTML output can smuggle active content through the to_markdown() path — applications relying on this conversion for safe content rendering should upgrade to 1.12.0 immediately.
7
CVE-2026-7808CVSS 9.3affects justhtml
Multiple HTML sanitization bypass issues in justhtml before 1.16.0 allow script or style content to survive sanitization under advanced usage patterns, including reuse of policy objects — organizations using customized sanitization policies are most exposed and should audit their sanitizer configurations alongside upgrading.
8
CVE-2026-5388CVSS 9.3affects justhtml
justhtml before 1.15.0 contains compounding sanitization failures across URL helpers, HTML serialization, and Markdown passthrough — attackers can chain these to inject JavaScript via encoded URLs or backslash bypasses, and the breadth of affected code paths makes configuration-level mitigations unreliable without patching.
9
CVE-2026-78170HIGH 8.7PoCaffects HiPER 1200GW
A remotely exploitable buffer overflow in the UTT HiPER 1200GW via the ssid argument has a published exploit, placing this older device model at risk of code execution — if replacement is not feasible, restricting HTTP management access to trusted network segments is a critical compensating control.
10
CVE-2026-78208HIGH 8.7affects exceljs
A path traversal flaw in exceljs-hardened's Workbook.addImage() allows attackers to supply arbitrary file paths and embed any file accessible to the Node.js process into a generated workbook — this effectively becomes a server-side file read vulnerability in any application that processes user-supplied image paths.
Ransomware today

The ransomware group kazu recently claimed two Brazilian victims in the healthcare sector: Brazil Mobilemed, a Cloud PACS platform, and Meducar, a telemedicine and patient management system — both sensitive targets given the nature of medical imaging and patient data they handle. The group thegentlemen added UOLconsult, a professional services firm, to its list. Over the past 30 days, Section9 and thegentlemen have been the most active groups targeting Brazil, each with six confirmed victims, followed by Global Secret Group with four.

Brazil Mobilemed: Cloud PACS Platform BRkazu · Healthcare
Meducar: Telemedicine and Patient Management System BRkazu · Healthcare
UOLconsult BRthegentlemen · Professional Services
Section9 6thegentlemen 6Global Secret Group 4direwolf 2L Group 2kazu 2
Active groups & APTs

Several threat actor groups are currently being tracked as active or recently updated, including dragonforce, funksec, kairos, karakurt, kazu, and the Iranian-linked group blackshadow. While no new confirmed victims are attributed to these actors in the current reporting window, their continued activity signals ongoing reconnaissance and targeting operations that defenders should account for, particularly given the overlap with known Brazilian victims.

Brazil focus

Brazil continues to face significant ransomware pressure across multiple sectors in the past 30 days. Beyond the fresh healthcare hits by kazu, the country has seen attacks on government (Prefeitura Municipal de Arcos by emperador), technology firms (TOTVS by direwolf, tecnoabi.com by m3rx), legal services (VR Advogados by Barracuda), and Vermont XCenter by dragonforce — a breadth of targeting that indicates Brazilian organizations remain a high-priority region for ransomware operators regardless of industry vertical.

Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
UOLconsultthegentlemen · Professional Services
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
VR AdvogadosBarracuda · Professional Services
TOTVSdirewolf · Technology
tecnoabi.comm3rx · Technology
Today’s recommendation: Prioritize patching the ipTIME authentication bypass flaws (CVE-2026-78167 and CVE-2026-78168) and the StackGres privilege escalation (CVE-2026-78155) immediately, as these carry the highest CVSS scores and are either already publicly exploited or trivially reproducible; simultaneously audit all justhtml and exceljs-hardened deployments to ensure version thresholds are met, particularly where user-supplied content is processed.
The breadth of today's critical CVEs across network hardware, cloud-native operators, and developer libraries is a reminder that knowing which of these components exist in your environment — and whether they face the internet or handle untrusted input — is the first step to meaningful risk reduction.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share