Daily briefing · September 3, 2026
Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 3, 2026 brings no active exploitation or weaponized exploits, but the day's vulnerability catalog is far from routine: four CVEs have earned the maximum CVSS score of 10.0, spanning ASUS hardware management, Microsoft Azure services, and a widely used web mapping library. With 349 new CVEs published and 47 rated critical, defenders should treat this as a prioritization exercise, not a rest day.
Today’s brief
- Four CVSS 10.0 vulnerabilities disclosed today across ASUS Control Center, Microsoft Entra (Azure AD B2C), Azure AI Language, and MapLibre GL JS.
- No active exploitation (KEV) confirmed today, but the severity ceiling is at maximum — patching windows are short once PoCs emerge.
- Multiple WordPress ecosystem plugins (JobSearch, Bricksforge, Mail Mint, YITH WooCommerce) carry unauthenticated critical flaws affecting millions of potential sites.
- Brazil faces fresh ransomware pressure: four new victims identified recently, spanning manufacturing, healthcare, and other sectors.
Critical highlights
1
A devastating triple-flaw chain in ASUS Control Center Enterprise — missing authentication, SSRF, and hardcoded credentials — allows any unauthenticated attacker to retrieve an encryption key via HTTP, trigger SSH on port 2222, and log in with static credentials to obtain a root shell with full read/write/delete access. This is effectively a one-step remote root compromise on any exposed ACC instance.
2
A user-controlled key authorization bypass in Microsoft Azure Active Directory B2C enables unauthenticated network attackers to escalate privileges within Entra environments. The CVSS 10.0 score reflects the lack of any required authentication or user interaction, making this a high-priority patch for any organization running Azure AD B2C tenants.
3
Missing authentication for a critical function in Azure AI Language Authoring allows unauthenticated remote attackers to elevate privileges over the network. Organizations using Azure AI Language services for content or NLP workloads should verify patch status immediately, as the absence of any authentication requirement lowers the exploitation bar to near zero.
4
A DOM sanitization logic flaw in MapLibre GL JS (pre-6.4.1) allows an attacker who controls map style attribution strings or custom map data to inject dangerous attributes that survive sanitization due to live-collection index shifting during attribute removal. Any web application rendering user-supplied or third-party map styles is potentially exposed to DOM-based attacks.
5
Unauthenticated PHP Object Injection in the JobSearch WordPress plugin (versions up to 3.2.0) allows remote attackers to trigger object deserialization without any credentials, potentially leading to remote code execution depending on available gadget chains in the environment. WordPress sites using this plugin should update immediately.
6
A subscriber-level privilege escalation flaw in Bricksforge (up to 3.1.8.8) allows low-privileged authenticated users to gain elevated access on WordPress sites. While requiring a basic account, subscriber-level access is trivially obtainable on sites with open registration, making this practically close to unauthenticated in many real-world deployments.
7
Unauthenticated PHP Object Injection in Mail Mint (up to 1.31.0) mirrors the risk profile of CVE-2026-84834 — no credentials required, and exploitation severity depends on installed PHP libraries that may provide deserialization gadgets. Email marketing plugins are attractive targets due to their access to subscriber data and server-side processing.
8
CVE-2026-84238CVSS 9.8affects YITH Request a Quote for WooCommerce Premium An unauthenticated broken access control flaw in YITH Request a Quote for WooCommerce Premium (pre-4.46.0) allows unauthorized users to access or manipulate quote functionality. E-commerce sites running this plugin on WooCommerce should prioritize the update, as exposed quote data may include sensitive pricing or customer information.
9
Improper input validation in the Transactions Platform component of Google Chrome on iOS (pre-152.0.7977.82) allows a remote attacker to potentially execute arbitrary code outside the browser sandbox via a crafted HTML page. The sandbox escape aspect is the critical concern — update Chrome on iOS endpoints promptly.
10
A use-after-free vulnerability in Chrome's DevTools (pre-152.0.7977.82) enables remote code execution outside the sandbox via a crafted page. DevTools-accessible memory corruption vulnerabilities are particularly concerning in enterprise environments where developer tools may be left enabled on production-facing browsers.
Ransomware today
Brazil is under sustained ransomware pressure: recently identified victims include Engefitas (manufacturing, hit by Vexy Ransomware), ialegre.com (attributed to settra), Oportunidados (claimed by direwolf), and paipharma.com in the healthcare sector (attributed to BrainCipher). Over the past 30 days, thegentlemen leads activity in Brazil with six known victims, followed by krybit (4), direwolf (3), and dragonforce (2), illustrating that Brazil-focused ransomware operations are both diverse and persistent.
Engefitas BRVexy Ransomware · Manufacturing
ialegre.com BRsettra · Other
Oportunidados BRdirewolf
paipharma.com BRBrainCipher · Healthcare
thegentlemen 6krybit 4direwolf 3emperador 2dragonforce 2L Group 2
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and blackshadow (of Iranian origin). While no new confirmed victims are attributed to these groups in the current data window, their monitored status signals ongoing reconnaissance or operational preparation — defenders in sectors historically targeted by Iranian actors should remain especially alert.
Brazil focus
Brazil continues to appear disproportionately in ransomware victim lists, with recent incidents spanning manufacturing (Engefitas), healthcare (paipharma.com, Exacta Optech Labcenter), and other sectors (frm.ind.br, Uniguacu, Oportunidados). The breadth of affected industries and the number of distinct ransomware groups involved — including BrainCipher, thegentlemen, emperor, and ZaWoo — suggests that Brazilian organizations across verticals remain high-value targets with insufficient defensive coverage.
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
frm.ind.brZaWoo · Other
Exacta Optech Labcenterthegentlemen · Healthcare
Uniguacuemperador · Other
amzur.comunsafe
Today’s recommendation: Prioritize patching the four CVSS 10.0 vulnerabilities today, starting with ASUS Control Center Enterprise (which offers a direct unauthenticated root path) and the two Microsoft Azure services, followed by the Chrome sandbox escapes and the WordPress plugin cluster. Where immediate patching is not possible, restrict network exposure of affected services and monitor for anomalous authentication or privilege escalation events.
Even on a day without confirmed active exploitation, the gap between disclosure and weaponization is shrinking — now is the moment to validate whether any of these affected products exist in your environment before that window closes.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →