Daily briefing · August 29, 2026
Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer Brazil
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention
August 29, 2026 carries a strong ATTENTION verdict: all ten highlighted vulnerabilities are confirmed in active exploitation by both CISA KEV and VulnCheck, spanning critical SQL injection, authentication bypass, and remote code execution flaws across widely deployed platforms. No new CVEs were recorded on the civil day itself, but the backlog of actively weaponized flaws demands immediate defensive action. Several were armed within one to two days of disclosure, underscoring how rapidly threat actors are converting research into operational attacks.
Today’s brief
- All 10 featured CVEs are confirmed in active exploitation — CISA KEV and VulnCheck both agree
- Metabase (CVSS 10.0) and mlflow (functional exploit, armed in 1 day) are the most urgent patch targets
- N-central authentication bypass has an incomplete patch (CVE-2026-18577) — the fix for CVE-2026-18556 is insufficient; update again
- Brazil is under concentrated ransomware pressure: krybit, thegentlemen, and unsafe hit healthcare, retail, tech, and manufacturing
Critical highlights
1
CVSS 10.0 with a functional exploit armed in just 2 days — unauthenticated attackers can inject arbitrary SQL via Metabase's password-reset endpoint and instantly seize administrator access to any connected database; patch or isolate Metabase instances immediately.
2
A state-management flaw in macOS Screen Sharing allows a network-adjacent attacker to authenticate without valid credentials; affects macOS Sequoia, Sonoma, and Tahoe — apply the vendor-supplied OS updates without delay.
3
TrueConf Server (multiple 5.x branches) exposes port 4307/TCP to unauthenticated remote code execution via a crafted script that breaks out of the isolated environment; network segmentation and immediate patching are critical for on-premises video-conferencing infrastructure.
4
An SSRF bypass in MLflow's webhook delivery mechanism was armed in just 1 day with a functional exploit — an unauthenticated attacker can redirect validated URLs to internal resources; organizations running AI/ML pipelines on mlflow below 3.15.0 should upgrade urgently.
5
A companion flaw to CVE-2026-72530, this TrueConf Server vulnerability allows unauthenticated remote attackers to execute arbitrary scripts by invoking an undocumented internal function via port 4307/TCP — treat both CVEs as a combined critical exposure.
6
CVE-2026-73570KEVHIGH 8.9Functional exploit8 daysaffects Collaboration Zimbra Collaboration before 10.1.20 is vulnerable to unauthenticated RCE when the optional zimbra-snmp package is active; a functional exploit was ready in 8 days and SMTP-crafted payloads can execute OS commands — disable SNMP notifications or upgrade immediately.
7
CVE-2026-20349KEVHIGH 8.6affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Cisco ASA and FTD SSL VPN services are susceptible to a remotely triggered reload causing denial of service; with no authentication required, this is a high-impact availability risk for perimeter security devices that are often internet-exposed.
8
This CVE represents an incomplete patch for CVE-2026-18556 in N-able N-central — defenders who already applied the prior fix are still vulnerable to authentication bypass and account takeover; a second update to a version beyond 2026.3.1 is mandatory.
9
The original N-central authentication bypass (armed in 5 days, EPSS 40%) allows complete account takeover via an alternate path or channel; given that the subsequent patch was also bypassed (CVE-2026-18577), treat this product as critically exposed until fully remediated.
10
A use-after-free in the Windows Ancillary Function Driver for WinSock enables local privilege escalation on Windows 10 1607; armed in just 2 days, this is a reliable post-exploitation stepping stone for attackers who already have a foothold on a Windows endpoint.
Ransomware today
Ransomware activity targeting Brazil has intensified recently, with the krybit group alone claiming three Brazilian victims — neooftalmo.com.br (Healthcare), sysconth.com (Technology), and vascara.com (Retail & E-Commerce). The thegentlemen group hit TEC Container in Manufacturing, while unsafe claimed amzur.com; over the past 30 days, thegentlemen leads overall Brazilian victim counts with 7 confirmed cases, followed by krybit with 4.
amzur.com BRunsafe
www.neooftalmo.com.br BRkrybit · Healthcare
sysconth.com BRkrybit · Technology
vascara.com BRkrybit · Retail & E-Commerce
TEC Container BRthegentlemen · Manufacturing
thegentlemen 7krybit 4direwolf 2dragonforce 2L Group 2kazu 2
Active groups & APTs
Several threat actor groups are being actively tracked, including dragonforce, funksec, kairos, karakurt, kazu, and the Iran-linked blackshadow. While no new confirmed victims are attributed to these groups in the current window, their continued monitoring reflects ongoing operational readiness and the potential for rapid escalation — kazu in particular has recently been linked to attacks on Brazilian healthcare targets.
Brazil focus
Brazil is facing a concentrated and multi-sector ransomware campaign: healthcare organizations such as neooftalmo.com.br, Brazil Mobilemed, and Meducar have been hit, alongside technology firm sysconth.com, retailer vascara.com, and manufacturer TEC Container. The breadth of targeted sectors — from cloud PACS platforms to telemedicine systems — signals that Brazilian organizations across all industries should treat the current threat level as elevated and review their incident response readiness.
amzur.comunsafe
sysconth.comkrybit · Technology
www.neooftalmo.com.brkrybit · Healthcare
vascara.comkrybit · Retail & E-Commerce
TEC Containerthegentlemen · Manufacturing
Fratodragonforce · Other
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
Today’s recommendation: Prioritize patching Metabase (CVE-2026-72898), mlflow (CVE-2026-64849), and both N-central CVEs (CVE-2026-18556 and CVE-2026-18577) immediately, as functional exploits are confirmed in the wild; simultaneously, audit TrueConf Server and Zimbra deployments for exposure and restrict port 4307/TCP at the network perimeter.
Given the volume of actively exploited vulnerabilities across such diverse platforms — from AI pipelines to VPN appliances — now is the moment to validate whether any of these affected products exist in your environment and confirm that compensating controls are actually in place.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →