Daily briefing · September 6, 2026
Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand Attention
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 6, 2026 registers a calm vulnerability day by the numbers — no weaponized exploits, no active KEV exploitation — but the disclosure list carries four critical-severity CVEs, three of them with public proof-of-concept code already available. Meanwhile, ransomware groups are actively targeting Brazilian organizations across multiple sectors, keeping the overall threat landscape far from relaxed.
Today’s brief
- Three Tenda HG10 critical flaws (OS command injection + buffer overflows) have public PoC — embedded/router defenders should prioritize immediately
- NEC UNIVERGE IX-R/IX-V authentication bypass allows unauthenticated CLI command execution over the internet — patch or restrict WebGUI access now
- OpenMAIC SSRF bypass exposes cloud metadata credentials in non-production builds — a serious misconfiguration risk in dev/staging pipelines
- Brazil-focused ransomware activity is intense: thegentlemen, Vexy Ransomware, and settra all claimed Brazilian victims in recent days
Critical highlights
1
OS command injection in Tenda HG10's formgponConf handler via the fmgpon_loid argument, exploitable remotely with a public exploit already available — any internet-exposed HG10 device should be considered at high risk of immediate compromise.
2
A buffer overflow in Tenda HG10's formURL handler triggered by the Keywd/urlFQDN arguments allows remote exploitation, with the exploit publicly disclosed — this device model now has multiple critical attack surfaces exposed simultaneously.
3
Authentication bypass in the WebGUI of NEC UNIVERGE IX-R/IX-V routers lets unauthenticated remote attackers execute arbitrary CLI commands by manipulating WebGUI messages — a complete perimeter breach risk for any internet-facing management interface.
4
OpenMAIC before 1.0.1 skips SSRF validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services and harvest cloud credentials — a dangerous oversight that can bridge a dev environment to a full cloud account takeover.
5
The SureCart WordPress plugin before 4.6.3 allows subscriber-level users to hijack any account, including administrator accounts, by changing their email address — a privilege escalation path to full site compromise that is trivial to automate.
6
PostgreSQL Anonymizer before 3.1.4 allows unprivileged masked users to execute arbitrary code with elevated privileges by abusing operators, domain casts, or view subqueries — databases relying on this extension for data masking may be exposing themselves to insider or multi-tenant attacks.
7
A third critical buffer overflow in Tenda HG10 — this time in formWanRedirect via the 'if' argument — is remotely exploitable with a public PoC, compounding the already serious attack surface of this device across three separate CVEs disclosed on the same day.
8
The h3 HTTP library before 2.0.1-rc.18 is vulnerable to a denial-of-service condition: a crafted cookie with an inflated chunk count triggers an O(n²) cleanup loop that can hang any server process built on this library.
9
PocketMine-MP before 4.7.2 crashes on malformed skin geometry JSON sent via login or skin packets, allowing unauthenticated attackers to trivially take down game servers by sending a single malicious packet.
10
A missing quantity validation in ZenHive mpp lets unauthenticated remote clients inflate gas costs for a fee-payer by a large multiplier and redirect EIP-7702 account delegations — a financial manipulation risk for any platform sponsoring Tempo payments through this library.
Ransomware today
Ransomware activity targeting Brazil is notably elevated in this reporting period. Three Brazilian organizations were recently claimed as victims: Lider Aviacao (Transportation) by thegentlemen, Engefitas (Manufacturing) by the emerging Vexy Ransomware group, and ialegre.com by settra. Among groups active over the past 30 days, thegentlemen stands out with seven victims — all in Brazil — making it the most Brazil-focused threat actor in current tracking.
Lider Aviacao BRthegentlemen · Transportation
Engefitas BRVexy Ransomware · Manufacturing
ialegre.com BRsettra · Other
thegentlemen 7direwolf 3krybit 3emperador 2dragonforce 2L Group 2
Active groups & APTs
Several threat actor groups are being monitored for updated activity, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iran-linked blackshadow — none currently with publicly attributed victims in this cycle, but their tracking reflects ongoing intelligence interest. dragonforce also appears in the 30-day ransomware activity rankings with two Brazilian victims, suggesting operational overlap between tracked APT infrastructure and active ransomware campaigns.
Brazil focus
Brazil is under sustained ransomware pressure across diverse sectors: beyond the three most recent victims, the broader 30-day picture includes paipharma.com and Exacta Optech Labcenter in Healthcare, frm.ind.br and Uniguacu in other sectors, and Oportunidados claimed by direwolf. The concentration of thegentlemen activity exclusively within Brazil (seven of seven known victims) is a strong indicator of deliberate targeting of Brazilian organizations, warranting heightened vigilance from local security teams.
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
Exacta Optech Labcenterthegentlemen · Healthcare
frm.ind.brZaWoo · Other
Uniguacuemperador · Other
Today’s recommendation: Prioritize patching or isolating Tenda HG10 devices and NEC UNIVERGE IX-R/IX-V WebGUI interfaces immediately, as the combination of critical CVSS scores and public exploit availability makes these prime candidates for rapid weaponization; simultaneously audit OpenMAIC deployments and SureCart WordPress installations for the disclosed privilege escalation and SSRF risks.
Given the mix of router-level, cloud-infrastructure, and application-layer vulnerabilities disclosed today — alongside active ransomware targeting of Brazilian organizations — now is the right moment to systematically validate whether your own attack surface exposes any of these affected technologies or similar misconfiguration patterns.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →