Daily briefing · August 26, 2026
Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emerge
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA
August 26, 2026 brings an ATTENTION-level verdict: two vulnerabilities are under active exploitation with VulnCheck detections preceding official CISA acknowledgment, signaling real-world attacker interest ahead of formal confirmation. A wave of CVSS 10.0 and 9.9 critical flaws across Ubiquiti's UniFi ecosystem — covering Protect, Access, Talk, and Cloud Gateways — demands immediate attention from network defenders. A functional exploit for a Gitea remote code execution flaw and a same-day-weaponized WordPress plugin credential leak round out a high-pressure advisory day.
Today’s brief
- Two CVEs flagged by VulnCheck before CISA: Gitea RCE (CVE-2026-60004) and WordPress TranslatePress credential leak (CVE-2026-19632) — treat as actively exploited.
- Four CVSS 10.0 flaws across Ubiquiti UniFi (Talk, Cloud Gateways, Protect, KubePi) enable unauthenticated command injection or auth bypass from network access.
- Gitea before 1.27.1 has a functional exploit for remote code execution via the diffpatch API — patch immediately if self-hosting.
- Brazil is heavily targeted by ransomware groups krybit, kazu, and thegentlemen, with healthcare and tech sectors taking the hardest hits recently.
Critical highlights
1
CVE-2026-19632◆ VulnCheckCVSS 9.8PoCsame dayaffects TranslatePress – Translate Multilingual sites with AI Translation A critical WordPress plugin flaw in TranslatePress (up to 3.3.1) allows unauthenticated attackers to retrieve the raw administrator password-reset URL — including the plaintext reset key — via an AJAX action, effectively handing over account takeover capability. VulnCheck detected exploitation before CISA, and the vulnerability was weaponized the same day it was disclosed, making this an emergency patch for any WordPress site using this plugin.
2
Gitea before 1.27.1 contains a remote code execution flaw exploitable through the diffpatch API via Git hook installation; a functional exploit exists and VulnCheck flagged active exploitation ahead of CISA. Any organization self-hosting Gitea for source code management should treat this as an immediate emergency, as a successful exploit grants full code repository access and likely lateral movement into CI/CD pipelines.
3
KubePi (up to version 1.6.15) exposes SSO, OIDC, and SAML configuration API endpoints on the same public routing boundary as login endpoints, allowing unauthenticated actors to read, create, or modify global SSO settings. With a CVSS score of 10.0, this effectively enables identity provider takeover across all clusters managed through the panel.
4
UniFi Talk Application is vulnerable to command injection via improper input validation, exploitable by any actor with network access — no credentials required. CVSS 10.0 makes this a top-priority patch for environments where UniFi Talk is internet-adjacent or accessible on untrusted network segments.
5
A CRLF injection vulnerability in UniFi OS running on certain Cloud Gateway devices allows network-adjacent attackers to bypass authentication entirely, achieving unauthenticated access to the device or OS instance. With a CVSS of 10.0 and no privilege requirement, this is a critical exposure for perimeter devices.
6
UniFi Protect Application is affected by an improper input validation vulnerability that allows unauthenticated, network-accessible attackers to execute arbitrary commands on the host device. Physical security infrastructure running Protect should be isolated from untrusted networks immediately pending patching.
7
A second command injection flaw in UniFi Protect Application (CVSS 9.9) requires only low privileges and network access, lowering the exploitation bar significantly compared to CVE-2026-77537. Defenders should assume that any low-privileged user on the same network segment is a potential threat actor for this device.
8
UniFi Access Application contains an improper access control flaw (CVSS 9.9) exploitable by low-privileged network users to escalate privileges on the host device. Physical access control systems compromised via this vector could allow attackers to manipulate door or entry point management.
9
Another command injection vulnerability in UniFi Protect Application (CVSS 9.9) allows low-privileged network actors to execute arbitrary commands on the host. This represents the third critical flaw in UniFi Protect this advisory cycle, indicating a systemic input validation deficiency in the product.
10
UniFi Access Application is also affected by a command injection flaw (CVSS 9.9) exploitable with low privileges from the network, enabling host-level code execution. Organizations running Ubiquiti physical access infrastructure should apply vendor patches and enforce strict network segmentation as a compensating control.
Ransomware today
The krybit group has been particularly active against Brazilian targets recently, claiming victims across healthcare (www.neooftalmo.com.br), technology (sysconth.com), and retail (vascara.com). The kazu group also struck the Brazilian healthcare sector, listing Brazil Mobilemed's Cloud PACS Platform and Meducar's telemedicine system as victims — a troubling concentration of attacks on medical data infrastructure. Additionally, thegentlemen claimed TEC Container (manufacturing) and UOLconsult (professional services), while dragonforce hit Frato, underscoring Brazil's position as a primary ransomware target across multiple active groups.
www.neooftalmo.com.br BRkrybit · Healthcare
sysconth.com BRkrybit · Technology
vascara.com BRkrybit · Retail & E-Commerce
TEC Container BRthegentlemen · Manufacturing
Frato BRdragonforce · Other
Brazil Mobilemed: Cloud PACS Platform BRkazu · Healthcare
Meducar: Telemedicine and Patient Management System BRkazu · Healthcare
thegentlemen 7krybit 4Global Secret Group 2dragonforce 2L Group 2direwolf 2
Active groups & APTs
Several threat actor groups are currently being tracked with updated activity profiles, including dragonforce, funksec, kairos, karakurt, and kazu, as well as the Iranian-linked blackshadow group. While no new confirmed victims are attributed to these actors in the current window, their active monitoring status signals that defenders — particularly in sectors targeted by these groups historically — should maintain heightened vigilance. DragonForce in particular has confirmed recent Brazilian victims, reinforcing its regional operational focus.
Brazil focus
Brazil is experiencing an intense ransomware campaign across multiple sectors, with at least eight organizations identified as recent victims across healthcare, technology, retail, manufacturing, and professional services. The concentration of krybit attacks on healthcare and tech, combined with kazu targeting cloud-based medical platforms like Brazil Mobilemed and Meducar, signals a deliberate focus on high-value data environments where operational disruption carries maximum leverage. Organizations in Brazil's healthcare and critical service sectors should treat the current threat level as elevated and prioritize incident response readiness.
vascara.comkrybit · Retail & E-Commerce
sysconth.comkrybit · Technology
www.neooftalmo.com.brkrybit · Healthcare
TEC Containerthegentlemen · Manufacturing
Fratodragonforce · Other
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
UOLconsultthegentlemen · Professional Services
Today’s recommendation: Organizations running any Ubiquiti UniFi product (Protect, Access, Talk, Cloud Gateways) should apply vendor patches immediately and enforce strict network segmentation to limit exposure to network-adjacent exploitation vectors; Gitea instances must be upgraded to 1.27.1 or later without delay given the functional exploit in circulation. WordPress administrators using TranslatePress should update to a patched version as a matter of urgency, as the combination of unauthenticated access and same-day weaponization makes exploitation highly likely in the wild.
With multiple CVSSs at 10.0 and active exploitation signals already outpacing official advisories, now is the time to validate whether any of these affected products exist in your environment and confirm they are patched — assumptions about what is and isn't exposed are a liability defenders cannot afford today.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →