Daily briefing · September 4, 2026

WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 4, 2026 registers as a calm day in terms of active exploitation — no vulnerabilities were weaponized, no KEV additions, and no VulnCheck early signals — but the volume of critical disclosures remains notable, with 37 critical CVEs among 506 newly published. The day's highlights cluster around unauthenticated attack vectors in WordPress plugins and a batch of stack-based buffer overflows in FreeIPMI, all carrying CVSS 9.8 scores that demand prompt patching attention. Defenders should not let the absence of active exploitation translate into complacency: several of these flaws already have proof-of-concept code available.

Today’s brief
  • No active exploitation or KEV additions recorded today — veredito is CALM, but 37 critical CVEs were disclosed
  • WordPress plugins dominate: unauthenticated RCE, LFI, and privilege escalation flaws affect AI Website Builder, Divi Ajax Filter, and ACPT Premium
  • FreeIPMI ships five stack-based buffer overflows (CVE-2026-85509, -85508, -85507, -85506, -85504) all rated CVSS 9.8 — patch to 1.6.19 immediately
  • Brazil faces intensifying ransomware pressure: four new victims across manufacturing, healthcare, and other sectors identified in recent days
37
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-82923CVSS 9.8PoCaffects AI Website Builder (GitHub build)
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 exposes unauthenticated REST API routes allowing attackers to install arbitrary plugins/themes, import remote content, write files to the uploads directory, and delete site media — on PHP-enabled hosts, this effectively means unauthenticated remote code execution. A proof of concept is already available, raising the urgency for any site running this build.
2
CVE-2026-11613CVSS 9.8PoCsame dayaffects Divi Ajax Filter
The Divi Ajax Filter plugin (all versions through 5.1.2) is vulnerable to unauthenticated Local File Inclusion via the 'custom_loop_template' parameter, enabling execution of arbitrary PHP files on the server. Critically, this flaw was weaponized on the same day it was disclosed, meaning exploit code reached attackers before most defenders could act — treat this as an emergency patch.
3
CVE-2026-85509CVSS 9.8affects FreeIPMI
FreeIPMI before 1.6.19 contains a stack-based buffer overflow in _read_fru_data triggered when a BMC returns more bytes than requested, allowing a malicious or compromised BMC to crash or potentially execute code in the context of the IPMI management utilities. All five FreeIPMI CVEs share the same fix target (1.6.19) and affect out-of-band server management infrastructure.
4
CVE-2026-85508CVSS 9.8affects FreeIPMI
The ipmi-oem tool in FreeIPMI before 1.6.19 overflows a stack buffer when processing Dell CMC IPv6 information responses, a vector reachable if an attacker controls or spoofs the BMC reply. Combined with the other FreeIPMI flaws disclosed today, this represents a significant attack surface for data-center management networks.
5
CVE-2026-85507CVSS 9.8affects FreeIPMI
Another stack-based buffer overflow in ipmi-oem's Dell CMC info subcommand (FreeIPMI < 1.6.19); exploitation requires interaction with a malicious or attacker-controlled BMC endpoint but can result in process memory corruption and potential code execution in privileged management contexts.
6
CVE-2026-85506CVSS 9.8affects FreeIPMI
FreeIPMI's ipmi-oem is also vulnerable via the Dell idrac-info subcommand, where _get_dell_system_info_idrac_info overflows a stack buffer on crafted iDRAC responses. Organizations running Dell server fleets with FreeIPMI tooling should prioritize upgrading to 1.6.19 across all four Dell-specific buffer overflow CVEs.
7
CVE-2026-85504CVSS 9.8affects FreeIPMI
A fifth FreeIPMI buffer overflow, this one in the SEL parsing code for Fujitsu iRMC systems, triggers on malformed Fujitsu SEL long-text responses — expanding the affected hardware scope beyond Dell to Fujitsu environments. Patch to FreeIPMI 1.6.19 resolves all five stack overflow issues disclosed today.
8
CVE-2026-15354CVSS 9.8affects ACPT (Premium)
The ACPT Premium WordPress plugin (through 2.0.66) allows unauthenticated attackers to overwrite any WordPress user's email address — including administrator accounts — via missing authorization in a form submission function, enabling full account takeover. This privilege escalation path requires no credentials and no user interaction beyond submitting a crafted request.
9
CVE-2026-18658CVSS 9.8affects Operational Decision Manager
IBM Operational Decision Manager across multiple versions (8.x and 9.x) is vulnerable to unauthenticated SQL injection that can be chained to write a web shell to the application root, yielding remote code execution. IBM ODM is commonly deployed in enterprise business-rules automation environments, and an unauthenticated RCE path in such a system represents a critical risk to sensitive business logic and data.
10
CVE-2026-85085CVSS 9.6affects Canva
The Canva Android app before version 2.376.0 permitted an external origin to load within a privileged WebView, allowing a threat actor controlling the loaded page to communicate with Canva using the victim's authenticated session — effectively hijacking the user's Canva account via a malicious link. Users should ensure the app is updated to 2.376.0 or later.
Ransomware today

Four new ransomware victims tied to Brazil have been identified recently: Engefitas (manufacturing) was hit by Vexy Ransomware, ialegre.com (other sector) by settra, Oportunidados by direwolf, and paipharma.com (healthcare) by BrainCipher. Among the most active groups over the past 30 days, thegentlemen leads with six attacks, all in Brazil, followed by direwolf, krybit, and emperor — a pattern that underscores a sustained and geographically focused ransomware campaign against Brazilian organizations.

Engefitas BRVexy Ransomware · Manufacturing
ialegre.com BRsettra · Other
Oportunidados BRdirewolf
paipharma.com BRBrainCipher · Healthcare
thegentlemen 6direwolf 3krybit 3emperador 2dragonforce 2L Group 2
Active groups & APTs

Several threat actor groups are being tracked as recently active or updated, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and the Iranian-linked blackshadow, though no confirmed victims are currently attributed to these actors in the latest data. Their presence in threat intelligence feeds signals continued reconnaissance or preparation activity that defenders — especially in sectors targeted by Iranian or hacktivism-aligned groups — should monitor closely.

Brazil focus

Brazil continues to draw disproportionate ransomware attention, with eight Brazilian victims recorded in recent weeks spanning manufacturing, healthcare, and other sectors — including Engefitas (Vexy Ransomware), paipharma.com (BrainCipher), Exacta Optech Labcenter (thegentlemen), and Uniguacu (emperador), among others. The concentration of attacks from groups like thegentlemen and direwolf, nearly all targeting Brazilian entities exclusively, suggests coordinated campaigns rather than opportunistic targeting, warranting heightened defensive posture for organizations operating in Brazil.

EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
frm.ind.brZaWoo · Other
Exacta Optech Labcenterthegentlemen · Healthcare
Uniguacuemperador · Other
amzur.comunsafe
Today’s recommendation: Prioritize patching FreeIPMI to version 1.6.19 to resolve all five stack buffer overflow CVEs, and immediately update or disable the Divi Ajax Filter plugin given its same-day weaponization. WordPress administrators should audit installed plugins against today's advisories, and IBM ODM operators should treat CVE-2026-18658 as a critical emergency given its unauthenticated RCE potential.
Even on a day without confirmed active exploitation, today's disclosures are a reminder that the gap between 'proof of concept published' and 'attacks in the wild' can close within hours — validating your own exposure to these asset classes before threat actors do is the most effective defensive move you can make.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share