Daily briefing · August 31, 2026

WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEs

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

August 31, 2026 closes with an ATTENTION-level verdict: while no new KEV entries were formally added, VulnCheck flagged CVE-2026-82970 as actively exploited before any CISA confirmation, underlining how real-world attacks outpace official advisories. The day produced 265 new vulnerabilities, 41 of them critical, with WordPress ecosystem components and Tenda home routers accounting for the bulk of the most dangerous disclosures. Defenders should treat several of these as operationally urgent given public proof-of-concept code and one confirmed pre-CISA exploitation signal.

Today’s brief
  • CVE-2026-82970: CVSS 10.0 unrestricted file upload in WP Cookie Notice — already seen exploited by VulnCheck before CISA confirmation
  • Three Tenda router CVEs (AC18, AC1206 ×2) carry CVSS 10.0 with public PoC exploits, all enabling unauthenticated remote access
  • Two additional WordPress plugins (Newspapers X, Hash Form, WPLP Cookie Consent) expose unauthenticated arbitrary file upload at critical severity
  • Dell PowerStore and MCPHub round out the critical list with authentication-bypass and remote code execution risks in enterprise environments
41
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-82970◆ VulnCheckCVSS 10affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
An unrestricted file upload flaw in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent (through 4.4.1) scored a perfect CVSS 10.0 and was flagged by VulnCheck as exploited in the wild before CISA issued any advisory — making this the highest-urgency item of the day; unauthenticated attackers can plant malicious files directly on affected WordPress sites.
2
CVE-2026-82971CVSS 10PoCaffects Opera11
A publicly disclosed command injection flaw in QVidium Opera11 3.3.2a26-Ax4x-opera11 allows remote attackers to inject OS commands via the CGI ipaddr parameter; the vendor has ceased operations, meaning no official patch will ever be released and exposed devices should be isolated immediately.
3
CVE-2026-81779CVSS 10affects Newspapers X
Newspapers X (versions 1.0.46–1.0.48) contains an improper input quantity validation flaw that enables malicious software implantation, rated CVSS 10.0; WordPress sites running affected versions should be updated or deactivated without delay.
4
CVE-2026-81780CVSS 10affects Hash Form
Hash Form versions up to 1.4.2 allow unauthenticated arbitrary file upload, a classic vector for web shell deployment and full site compromise; the CVSS 10.0 rating reflects the ease of exploitation requiring no credentials.
5
CVE-2026-82695CVSS 10PoCaffects AC18
A missing authentication vulnerability in the Telnet Handler (/goform/telnet) of Tenda AC18 firmware 15.03.05.19 has a public exploit and CVSS 10.0, granting any remote attacker unauthenticated access to the device's administrative telnet interface.
6
CVE-2026-82694CVSS 10PoCaffects AC1206
The R7WebsSecurityHandler function in Tenda AC1206 firmware 15.03.06.23 lacks authentication on the /goform/ate endpoint; a public exploit is available, making unauthenticated remote takeover trivial for any attacker with network access.
7
CVE-2026-82693CVSS 10PoCaffects AC1206
A second CVSS 10.0 flaw in Tenda AC1206 15.03.06.23 affects the TendaTelnet function, again removing authentication from a telnet-enabling endpoint; with a public PoC in circulation, these routers should be considered fully compromised if internet-exposed.
8
CVE-2026-79748CVSS 9.9affects mcphub
MCPHub prior to 0.12.15 allows authenticated users to spawn arbitrary system processes via the server configuration API, effectively enabling remote code execution in environments orchestrating MCP servers; upgrade to 0.12.15 or restrict API access immediately.
9
CVE-2026-58574CVSS 9.8affects PowerStore 1000T
Dell PowerStore contains a missing authentication vulnerability on its restricted management interface that could allow an unauthenticated network attacker to read internal filesystem data including credentials, potentially enabling full administrative control; no credentials required makes this particularly dangerous in poorly segmented storage networks.
10
CVE-2026-75865CVSS 9.8affects WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
The WPLP Cookie Consent plugin for WordPress (through 4.4.1) combines missing file type validation with an authorization bypass on REST endpoints, enabling unauthenticated arbitrary file uploads; the overlap in version range and plugin category with CVE-2026-82970 suggests coordinated researcher attention on the GDPR consent plugin space.
Ransomware today

Several Brazilian organizations have been claimed as ransomware victims in recent days, with groups including thegentlemen, emperador, ZaWoo, and unsafe posting them to leak sites. Among the victims are Exacta Optech Labcenter in the healthcare sector (claimed by thegentlemen), Uniguacu (claimed by emperador), frm.ind.br (ZaWoo), and amzur.com (unsafe). Over the past 30 days, thegentlemen leads activity in Brazil with six confirmed claims, followed by krybit with four, reinforcing a sustained targeting pattern against Brazilian organizations across multiple sectors.

Uniguacu BRemperador · Other
Exacta Optech Labcenter BRthegentlemen · Healthcare
frm.ind.br BRZaWoo · Other
amzur.com BRunsafe
thegentlemen 6krybit 4emperador 2dragonforce 2L Group 2direwolf 2
Active groups & APTs

Several threat actor groups are currently being tracked as active or recently updated, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and the Iranian-linked blackshadow. While no new confirmed victims are attributed to these actors in the current reporting window, their monitored status indicates continued operational readiness and potential staging activity. Defenders in sectors historically targeted by Iranian threat actors should treat blackshadow's presence on tracking lists as a standing alert.

Brazil focus

Brazil continues to face concentrated ransomware pressure, with eight distinct Brazilian organizations appearing as victims across healthcare, technology, manufacturing, retail, and other sectors over the past 30 days. Healthcare targets such as Exacta Optech Labcenter and www.neooftalmo.com.br — both claimed by krybit or thegentlemen — highlight a deliberate focus on sensitive-data industries. The volume and diversity of affected sectors suggest Brazilian organizations of all sizes remain active targets and should prioritize incident response readiness alongside vulnerability patching.

Exacta Optech Labcenterthegentlemen · Healthcare
Uniguacuemperador · Other
frm.ind.brZaWoo · Other
amzur.comunsafe
sysconth.comkrybit · Technology
vascara.comkrybit · Retail & E-Commerce
TEC Containerthegentlemen · Manufacturing
www.neooftalmo.com.brkrybit · Healthcare
Today’s recommendation: Organizations running WordPress should audit all installed plugins against today's critical file-upload CVEs and disable affected versions immediately; Tenda router administrators must isolate or replace devices running vulnerable AC18 and AC1206 firmware given the availability of public exploits and the absence of authentication requirements for attack.
Given the number of unauthenticated remote exploitation paths disclosed today, now is the right time to validate what your actual attack surface looks like from an external perspective — before an attacker does it for you.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share