Daily briefing · August 25, 2026

VulnCheck Flags Active Exploitation in TYPO3 Powermail Before CISA; Adobe Campaign Faces Triple Critical RCE

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

August 25, 2026 carries an ATTENTION verdict: one vulnerability — CVE-2026-77136 in the TYPO3 powermail extension — was flagged by VulnCheck as actively exploited in the wild before any CISA confirmation, serving as an early warning that defenders cannot afford to ignore. Simultaneously, Adobe Campaign Classic absorbed three separate critical-severity vulnerabilities, two of them unauthenticated OS command injection chains rated CVSS 10.0, making patch validation for ACC deployments urgent. With 726 new CVEs published today and 64 rated critical, the attack surface is broad and the risk is real.

Today’s brief
  • CVE-2026-77136: VulnCheck-confirmed active exploitation of TYPO3 powermail before CISA listing — patch or disable now
  • Adobe Campaign Classic hit by three CVSS 10.0 flaws (two OS command injection, one SSRF-to-RCE) requiring no user interaction
  • Joomla miniOrange SAML SSO authentication bypass (CVSS 10.0) allows unauthenticated account takeover via loose PHP openssl_verify() check
  • NVIDIA OpenShell and Zephyr RTOS stack overflows round out a heavy critical CVE day
64
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-77136◆ VulnCheckCVSS 9.5affects Extension "powermail"
Unauthenticated Fluid template injection in the TYPO3 powermail extension allows anonymous users to render arbitrary server-side templates, leaking environment variables and configuration data — VulnCheck observed real-world exploitation before CISA acted, making this the most urgent patch of the day.
2
CVE-2026-79911CVSS 10PoCaffects N600R
A publicly disclosed stack-based buffer overflow in TOTOLINK N600R's CGI handler can be triggered remotely without authentication via a crafted Hostname argument, with a proof-of-concept already available — embedded routers running this firmware should be isolated or replaced immediately.
3
CVE-2026-76195CVSS 10affects Adobe Campaign Classic
Unauthenticated OS command injection in Adobe Campaign Classic (CVSS 10.0, scope changed) allows arbitrary code execution as the current user with no interaction required — any internet-facing ACC instance should be treated as critically exposed until patched.
4
CVE-2026-76197CVSS 10affects Adobe Campaign Classic
A second unauthenticated OS command injection path in Adobe Campaign Classic (CVSS 10.0) mirrors CVE-2026-76195 in severity and exploitability, reinforcing that ACC is under heavy scrutiny this release cycle and multiple attack vectors must be closed simultaneously.
5
CVE-2026-76193CVSS 10affects Adobe Campaign Classic
An SSRF vulnerability in Adobe Campaign Classic can be chained to achieve arbitrary code execution without user interaction (CVSS 10.0, scope changed), expanding the risk beyond data exfiltration to full system compromise in affected deployments.
6
CVE-2026-77998CVSS 10affects SAML SP Single Sign On – Login with ADFS extension for Joomla
A loose PHP openssl_verify() boolean check in miniOrange's SAML SP Single Sign On extensions for Joomla allows unauthenticated attackers to bypass authentication entirely via a crafted SAMLResponse, giving them account access on any site running versions below the fixed thresholds — this is a classic cryptographic verification shortcut with maximum exploitability.
7
CVE-2026-65083CVSS 9.9affects OpenShell
NVIDIA OpenShell for Linux fails to fully enumerate disallowed inputs in its sandbox provisioning API, potentially enabling code execution, privilege escalation, and data tampering — organizations running OpenShell-based workloads on Linux should review NVIDIA's advisory and apply mitigations promptly.
8
CVE-2026-65093CVSS 9.9affects OpenShell
A sandbox escape vulnerability in NVIDIA OpenShell for Linux (CVSS 9.9) complements CVE-2026-65083 and could allow an attacker already inside a container or restricted environment to break containment and gain broader system access.
9
CVE-2026-13214CVSS 9.8affects zephyr
An unbounded strcpy() in Zephyr RTOS's OCPP 1.6 client causes a stack buffer overflow when processing attacker-controlled JSON key values from a central charging system, threatening EV charging infrastructure and any IoT deployments using this network library.
10
CVE-2026-78568CVSS 9.8affects Total Donations
Unauthenticated SQL injection in the Total Donations WordPress plugin (all versions through 2.0.5) allows attackers to extract sensitive database contents without any credentials — site owners should deactivate the plugin immediately if no patch is yet available.
Ransomware today

Recently, three Brazilian organizations were identified as ransomware victims: Frato (Other sector) claimed by DragonForce, and both Brazil Mobilemed (Cloud PACS Platform) and Meducar (Telemedicine and Patient Management System) in the healthcare sector claimed by the Kazu group. The targeting of two healthcare platforms by the same actor in close succession signals a deliberate campaign against Brazilian medical infrastructure. Among the most active groups over the past 30 days, Section9 and thegentlemen lead with six victims each — all in Brazil — underscoring the concentrated focus on Brazilian targets.

Frato BRdragonforce · Other
Brazil Mobilemed: Cloud PACS Platform BRkazu · Healthcare
Meducar: Telemedicine and Patient Management System BRkazu · Healthcare
Section9 6thegentlemen 6Global Secret Group 4dragonforce 2direwolf 2L Group 2
Active groups & APTs

Several threat actors are being actively tracked this period, including DragonForce, FunkSec, Kairos, Karakurt, Kazu, and the Iranian-linked BlackShadow group. While specific victim counts for this reporting window are not disclosed, the simultaneous tracking of six distinct groups — including a state-affiliated Iranian actor — indicates a diversified and active threat landscape. Defenders should monitor for indicators associated with these groups, particularly given DragonForce's and Kazu's demonstrated interest in Brazilian targets.

Brazil focus

Brazil continues to be a high-priority target for ransomware operators, with recent victims spanning healthcare (Brazil Mobilemed, Meducar), professional services (UOLconsult, VR Advogados), technology (TOTVS), and government (Prefeitura Municipal de Arcos). The attack on TOTVS, a major Brazilian ERP and software provider, is particularly significant given its widespread footprint across Brazilian enterprises. The concentration of attacks by groups such as Section9, thegentlemen, DragonForce, and Direwolf against Brazilian organizations reflects a sustained and deliberate targeting pattern.

Fratodragonforce · Other
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
UOLconsultthegentlemen · Professional Services
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
Today’s recommendation: Prioritize patching or disabling the TYPO3 powermail extension immediately given confirmed active exploitation, and apply Adobe Campaign Classic patches for all three critical CVEs before restoring any internet-facing access to those servers. Simultaneously audit Joomla SAML SSO extensions and WordPress plugin inventories for the affected versions and enforce network segmentation on vulnerable embedded devices such as the TOTOLINK N600R.
With multiple CVSS 10.0 vulnerabilities published today across marketing platforms, CMS extensions, and embedded routers, now is the right moment to validate whether your own external attack surface exposes any of these components before threat actors do it for you.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share