Daily briefing · August 30, 2026
Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 Bulletin
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
August 30, 2026 registers as a calm day by the numbers — no vulnerabilities in active exploitation, no weaponized exploits confirmed, and no VulnCheck-before-CISA early warnings — but the list of critical disclosures demands attention from defenders. A perfect-10 code injection in ash_ai and multiple public proof-of-concept buffer overflows in consumer routers from Tenda and D-Link illustrate that 'calm' does not mean 'safe.' Teams should treat today's batch as a patching backlog in the making.
Today’s brief
- CVE-2026-77956 scores CVSS 10.0: unauthenticated remote code execution in ash_ai via EEx template injection — patch or isolate immediately.
- Two D-Link DIR-825M and one TOTOLINK A720R stack-based buffer overflow PoCs are now public, lowering the bar for router-targeting attacks.
- WordPress plugin MyHome Core allows full authentication bypass for unauthenticated users on all versions up to 4.4.5 — high-traffic sites at risk.
- Brazil continues to absorb ransomware pressure: four new victims claimed recently by grupos emperador, thegentlemen, ZaWoo, and unsafe.
Critical highlights
1
A CVSS 10.0 remote code execution flaw in the ash_ai Elixir library allows any unauthenticated client to inject and execute arbitrary Elixir code through EEx template evaluation — the highest possible severity and a straightforward attack path that should be treated as critical remediation priority.
2
A proof-of-concept buffer overflow in the Tenda HG10 router's IPv6 routing handler is publicly available, enabling remote exploitation without authentication; unpatched devices exposed to the internet face a concrete, near-term threat.
3
The MyHome Core WordPress plugin (all versions through 4.4.5) allows unauthenticated attackers to generate activation tokens for unconfirmed accounts and obtain valid authentication credentials, effectively bypassing the login entirely — a critical risk for any WordPress site running this plugin.
4
A publicly disclosed stack-based buffer overflow in the D-Link DIR-825M 1.1.8 LTE firmware upgrade endpoint can be triggered remotely by manipulating the fota_url parameter, potentially leading to full device compromise.
5
A second stack-based buffer overflow in the D-Link DIR-825M 1.1.8 targets the disk formatting handler via the partition argument; with a public exploit available, attackers have a ready path to remote code execution on affected devices.
6
A publicly disclosed memory corruption vulnerability in TOTOLINK A720R's MAC filtering component can be triggered remotely through the desc argument, placing network access control integrity at risk on unpatched devices.
7
SiYuan before v3.8.1 fails to escape block names, aliases, and memos in multiple rendering functions, allowing a stored XSS payload to execute in any user's browser that views a document referencing the malicious block — a meaningful risk in collaborative note-taking environments.
8
A second stored XSS in SiYuan before v3.8.1 targets the bazaar package installation/uninstallation flow, where unescaped package names are written directly to innerHTML; a malicious package name can execute arbitrary scripts in victims' browsers.
9
AVideo exposes stream credentials — including stream keys and URLs for platforms such as YouTube and Facebook — through an unauthenticated endpoint bypass, allowing any attacker with knowledge of the flaw to harvest sensitive third-party streaming credentials.
10
Readest e-book reader versions prior to 0.11.16 apply an overly narrow DOMPurify configuration that misses srcdoc-based iframe payloads, meaning a malicious EPUB file can achieve cross-site scripting in the desktop app — a reminder that client-side document parsers are an often-overlooked attack surface.
Ransomware today
Several Brazilian organizations have been claimed as ransomware victims in recent days, including Uniguacu (attributed to emperador), Exacta Optech Labcenter in the healthcare sector (attributed to thegentlemen), frm.ind.br (attributed to ZaWoo), and amzur.com (attributed to unsafe). Over the past 30 days, thegentlemen leads activity with 8 known victims — all in Brazil — followed by krybit with 4 Brazilian victims, underscoring that domestic organizations remain a primary target for multiple active groups. The healthcare and technology sectors appear with particular frequency among recent Brazilian victims.
Uniguacu BRemperador · Other
Exacta Optech Labcenter BRthegentlemen · Healthcare
frm.ind.br BRZaWoo · Other
amzur.com BRunsafe
thegentlemen 8krybit 4emperador 2dragonforce 2L Group 2direwolf 2
Active groups & APTs
Several threat actors and APT-adjacent groups are currently being tracked as active or updated: dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and the Iranian-linked blackshadow are all flagged for monitoring despite no newly confirmed victims in this reporting cycle. The presence of blackshadow — a group with Iranian origins historically associated with disruptive operations — warrants continued vigilance from organizations in sectors it has targeted in the past.
Brazil focus
Brazil is experiencing sustained ransomware pressure across multiple sectors, with recent victims spanning healthcare (Exacta Optech Labcenter, www.neooftalmo.com.br), technology (sysconth.com), retail and e-commerce (vascara.com), manufacturing (TEC Container), and other industries. The concentration of attacks by thegentlemen and krybit specifically on Brazilian targets over the past 30 days suggests deliberate regional focus rather than opportunistic targeting. Organizations operating in Brazil should treat this pattern as a clear signal to review backup integrity, network segmentation, and incident response readiness.
Uniguacuemperador · Other
Exacta Optech Labcenterthegentlemen · Healthcare
frm.ind.brZaWoo · Other
amzur.comunsafe
sysconth.comkrybit · Technology
vascara.comkrybit · Retail & E-Commerce
TEC Containerthegentlemen · Manufacturing
www.neooftalmo.com.brkrybit · Healthcare
Today’s recommendation: Security teams should prioritize patching CVE-2026-77956 (ash_ai RCE) and CVE-2026-15980 (MyHome Core auth bypass) immediately, and audit any internet-facing Tenda HG10, D-Link DIR-825M, or TOTOLINK A720R devices for available firmware updates given the public availability of proof-of-concept exploits. Organizations running SiYuan or AVideo in collaborative or public-facing deployments should also apply available updates without delay.
Even on a statistically calm day, the combination of perfect-10 severity disclosures and multiple public proof-of-concepts is a reminder that understanding your own exposure requires actively validating which of these assets exist in your environment — not just waiting for exploitation confirmation.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →