Daily briefing · September 1, 2026
Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention3 seen before CISA
September 1, 2026 carries an ATTENTION-level verdict: while no vulnerability was formally weaponized with a ready exploit kit, three CVEs are under active exploitation and three were detected by VulnCheck before any CISA confirmation, underscoring that official channels continue to lag behind real-world attacker activity. The day's 453 new CVEs include 33 critical-rated entries, with standouts spanning authentication bypass in Proxmox VE, pre-auth SSRF and command injection in SonicWall SMA1000, and twin CVSS 10.0 flaws in HPE Networking Fabric Composer. Defenders should treat VulnCheck-flagged entries as operationally exploited and act accordingly.
Today’s brief
- 3 CVEs in active exploitation observed by VulnCheck before CISA confirmed them — patch without waiting for KEV.
- Proxmox VE authentication bypass (CVE-2023-54391) allows unauthenticated login as any enabled user — critical priority for virtualization teams.
- HPE Fabric Composer carries two CVSS 10.0 flaws (CVE-2026-76657, CVE-2026-76658) enabling unauthenticated full system takeover.
- Brazil is under sustained ransomware pressure — five new victims surfaced recently, including two in Healthcare.
Critical highlights
1
CVE-2023-54391◆ VulnCheckCVSS 9.3affects Proxmox Virtual Environment (VE) A CVSS 9.3 authentication bypass in Proxmox VE 7.0–8.0 lets any unauthenticated attacker log in as any enabled user without a second factor by supplying an arbitrary tfa-challenge value — VulnCheck flagged active exploitation before CISA, making this an immediate patching priority for anyone running Proxmox in production.
2
An OS command injection flaw in the SMA1000 Appliance Management Console (AMC) allows a remote authenticated administrator to achieve arbitrary code execution; with VulnCheck already observing exploitation ahead of any official advisory, environments exposing AMC remotely should isolate or patch urgently.
3
A pre-authentication SSRF in the SMA1000 Work Place interface requires no credentials and could allow attackers to pivot to internal services or sensitive functionality; combined with CVE-2026-83549, this creates a chained pre-to-post-auth attack path that VulnCheck has already observed being exploited.
4
A CVSS 10.0 flaw in the SSH daemon of HPE Networking Fabric Composer enables unauthenticated remote attackers to gain administrative access and execute arbitrary commands as a privileged user, resulting in complete host compromise — network segmentation should be enforced immediately while patches are applied.
5
A second CVSS 10.0 flaw in HPE Fabric Composer's API allows unauthenticated attackers to bypass all authentication controls and obtain administrative privileges; the dual 10.0 pair in this product signals systemic authentication design issues that warrant emergency remediation.
6
A CVSS 10.0 unauthenticated file upload vulnerability in a multi-tenant ERP system enables arbitrary file execution on the server, representing a critical risk to organizations sharing that infrastructure, since compromise of one tenant's API endpoint could cascade across the environment.
7
A CRLF injection flaw in the Predis PHP Redis client (versions 3.0.0-RC1 through 3.3.0) allows attacker-controlled keys or values to manipulate RESP protocol parsing in clustered and replication pipelines, with a CVSS of 9.8 — applications using Predis with untrusted input in Redis keys should upgrade to 3.3.0 immediately.
8
Multiple memory-handling vulnerabilities in an AOS-CX daemon allow unauthenticated remote attackers to send crafted packets and achieve remote code execution with elevated privileges (CVSS 9.8); HPE Aruba network infrastructure running AOS-CX should be treated as a high-priority patching target.
9
A CVSS 9.8 SQL injection vulnerability in TRtek's Products' Store e-commerce software allows unauthenticated attackers to extract or manipulate database contents; deployments on versions before the 030631b2 commit should be updated immediately given the ease of exploitation of classic SQLi.
10
A code injection vulnerability (CVSS 9.8) in Klemsan's KIO IoT platform allows attackers to inject and execute arbitrary code, posing serious risk in industrial and building-automation environments where KIO devices are often trusted and less scrutinized — versions before v1.9 are affected.
Ransomware today
Ransomware activity against Brazilian targets remains intense, with five victims surfacing recently across multiple groups: Oportunidados was claimed by direwolf, paipharma.com and Exacta Optech Labcenter — both in the Healthcare sector — were hit by BrainCipher and thegentlemen respectively, Uniguacu was claimed by emperador, and frm.ind.br by ZaWoo. Over the past 30 days, thegentlemen leads in Brazilian targeting with six known victims, followed by krybit (four), direwolf (three), and emperador and dragonforce with two each, painting a picture of coordinated, multi-group pressure on the Brazilian market.
Oportunidados BRdirewolf
paipharma.com BRBrainCipher · Healthcare
Uniguacu BRemperador · Other
Exacta Optech Labcenter BRthegentlemen · Healthcare
frm.ind.br BRZaWoo · Other
thegentlemen 6krybit 4direwolf 3emperador 2dragonforce 2L Group 2
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and blackshadow — the latter linked to Iran. While no confirmed new victims are attributed to these groups in the current data window, their continued monitoring status indicates operational readiness and potential for imminent activity, particularly from Iran-linked blackshadow given current geopolitical tensions.
Brazil focus
Brazil is experiencing a sustained ransomware campaign with at least eight organizations compromised in recent weeks, spanning Healthcare (paipharma.com, Exacta Optech Labcenter, neooftalmo.com.br), Technology (sysconth.com), and other sectors. The concentration of multiple active groups — thegentlemen, krybit, direwolf, BrainCipher, and others — all claiming Brazilian victims signals that the country remains a high-value target, and organizations in Healthcare and SME segments face elevated risk with little margin for unpatched exposure.
Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
Uniguacuemperador · Other
Exacta Optech Labcenterthegentlemen · Healthcare
frm.ind.brZaWoo · Other
amzur.comunsafe
sysconth.comkrybit · Technology
www.neooftalmo.com.brkrybit · Healthcare
Today’s recommendation: Prioritize immediate patching or isolation of Proxmox VE (CVE-2023-54391), SonicWall SMA1000 (CVE-2026-83548 and CVE-2026-83549), and HPE Fabric Composer (CVE-2026-76657 and CVE-2026-76658), as these combine critical severity with confirmed or VulnCheck-observed active exploitation. For all remaining CVSS 9.8–10.0 entries, enforce network-level access controls and accelerate patch cycles beyond standard maintenance windows.
Given the volume of unauthenticated attack paths disclosed today — spanning virtualization, networking, ERP, and IoT — now is the right moment to validate whether your own exposed services and asset inventory would withstand these techniques, before attackers do it for you.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →