Daily briefing · August 24, 2026
Calm Day Masks Growing Threat: 43 Critical CVEs Published and Ransomware Groups Intensify Focus on Brazil
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 24, 2026 was a relatively calm day from an exploitation standpoint — no active KEV entries, no weaponized exploits confirmed — but the publication of 326 new vulnerabilities, including 43 critical ones, keeps defenders busy. The highlights are dominated by a wave of critical WordPress plugin flaws and a perfect-10 vulnerability in OpenThread's MLE packet handling, all requiring prompt attention even in the absence of observed in-the-wild exploitation.
Today’s brief
- No active exploitation confirmed today, but 43 critical CVEs were published — patch queues just got longer.
- A CVSS 10.0 flaw in OpenThread (Nest) enables denial of service and stack buffer overflow on Thread networks.
- Multiple WordPress plugins — including TranslatePress, The Events Calendar, and WP Project Manager — carry unauthenticated critical flaws allowing privilege escalation or PHP object injection.
- Brazil is under sustained ransomware pressure: healthcare, government, and tech sectors hit recently by dragonforce, kazu, thegentlemen, and direwolf.
Critical highlights
1
A CVSS 10.0 stack-based buffer overflow and assertion failure in OpenThread's MLE packet handling allows an authenticated attacker on the same Thread network to crash or potentially compromise Nest devices. Although exploitation requires network adjacency, the maximum severity score demands immediate patching in any IoT/smart home deployment.
2
CVE-2026-77995CVSS 10affects miniOrange OAuth Client extension for Joomla An arbitrary account takeover in miniOrange OAuth Client for Joomla (versions below 3.2.0) lets attackers manipulate a cookie value to authenticate as any account, including site administrators. This effectively hands over full site control without credentials and should be treated as an emergency update for any Joomla site using this extension.
3
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit rights — or anyone launching a malicious image — to overwrite arbitrary host files as root, escaping container isolation entirely. Organizations using LXD in multi-tenant or shared environments face a severe host compromise risk.
4
Subscriber-level users on WordPress sites running UltimateAI 3.1.0 or earlier can upload arbitrary files, potentially deploying a web shell and achieving remote code execution. Any site with user registration enabled and this plugin installed should treat this as high-priority remediation.
5
TranslatePress 3.3.2 and below carries an unauthenticated privilege escalation flaw, meaning any internet visitor — without an account — can potentially gain elevated access to the WordPress site. Multilingual WordPress sites should update immediately or disable the plugin.
6
The Events Calendar plugin for WordPress (up to version 6.17.2) is vulnerable to unauthenticated PHP Object Injection, which can be chained with a suitable gadget chain to achieve remote code execution or data exfiltration. Given its widespread adoption, this flaw has significant mass-exploitation potential.
7
WP Project Manager 4.0.6 and below allows unauthenticated PHP Object Injection, exposing project management data and potentially leading to remote code execution depending on the server's installed PHP libraries. Sites should update or remove the plugin and audit for signs of prior compromise.
8
CVE-2026-32563CVSS 9.8affects ACPT (Pro) - Custom Post Types Plugin for WordPress Subscriber-level users on WordPress sites running ACPT (Pro) 2.0.63 or earlier can trigger PHP Object Injection, which may escalate into more severe impact if exploitable gadget chains are present in the environment. Update to a patched version and review subscriber account activity.
9
FreightCo 1.1.15 and below contains an unauthenticated PHP Object Injection vulnerability, requiring no authentication to trigger and posing a direct risk of remote code execution in shipping and logistics environments where this plugin is deployed.
10
The Jawn plugin for WordPress (up to version 1.4.2) allows unauthenticated privilege escalation, granting any external actor potential administrative access without credentials. Sites should remove or update the plugin immediately.
Ransomware today
Ransomware activity targeting Brazil has remained notably elevated in recent days. The group kazu claimed two healthcare victims — Brazil Mobilemed (a Cloud PACS platform) and Meducar (a telemedicine and patient management system) — signaling a deliberate focus on sensitive medical infrastructure. Dragonforce claimed Frato, while thegentlemen targeted UOLconsult, a professional services firm. Among the most active groups over the past 30 days, Section9, thegentlemen, and Global Secret Group each rank at the top, with Brazil consistently representing their primary targeting geography.
Frato BRdragonforce · Other
Brazil Mobilemed: Cloud PACS Platform BRkazu · Healthcare
Meducar: Telemedicine and Patient Management System BRkazu · Healthcare
UOLconsult BRthegentlemen · Professional Services
Section9 6thegentlemen 6Global Secret Group 4dragonforce 2direwolf 2L Group 2
Active groups & APTs
Several threat actor groups are currently being tracked with heightened attention: dragonforce, funksec, kairos, karakurt, kazu, and the Iranian-linked blackshadow are all flagged as active or recently updated in threat intelligence feeds. While no specific victim counts are attributed to each in this cycle, their operational status warrants monitoring — particularly dragonforce and kazu, given their confirmed recent activity against Brazilian targets.
Brazil focus
Brazil continues to face sustained and cross-sector ransomware pressure. Recent victims include Brazil Mobilemed and Meducar in healthcare (kazu), TOTVS — one of Brazil's largest tech companies — claimed by direwolf, UOLconsult by thegentlemen, VR Advogados by Barracuda, Prefeitura Municipal de Arcos (government) by emperador, and Vermont XCenter by dragonforce. The breadth of sectors targeted — government, healthcare, technology, and professional services — reflects an opportunistic and persistent threat environment for Brazilian organizations.
Fratodragonforce · Other
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
UOLconsultthegentlemen · Professional Services
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
Today’s recommendation: Prioritize patching the unauthenticated critical flaws in WordPress plugins (TranslatePress, The Events Calendar, WP Project Manager, FreightCo, Jawn) and the Joomla miniOrange OAuth extension, as these require zero authentication to exploit and are likely to be mass-scanned rapidly. Additionally, organizations running LXD or OpenThread-based devices should assess exposure and apply vendor patches or mitigations without delay.
Even on a calm exploitation day, understanding which of these newly published critical vulnerabilities exist within your own environment is the only way to determine whether 'calm' actually applies to you.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →