Daily briefing · September 7, 2026

22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazil

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 7, 2026 registers as a calm day from an exploitation standpoint — no vulnerabilities were weaponized, no active exploitation confirmed, and no VulnCheck early signals — but the volume of critical disclosures remains substantial, with 22 critical CVEs published in a single day. The top entries span SAP, Adobe Commerce, D-Link, JetBrains, and Red Hat, several carrying perfect CVSS scores. While no immediate fire drills are required, the breadth of affected enterprise and SMB products demands prompt patch triage.

Today’s brief
  • No active exploitation or weaponized exploits recorded today — patch window exists but is narrow
  • Two CVSS 10.0 SAP flaws and a CVE-2026-75650 Adobe Commerce RCE lead the day's critical disclosures
  • JetBrains Hub and YouTrack hit with unauthenticated privilege escalation and account takeover bugs
  • Brazil faces intense ransomware pressure: thegentlemen group claimed multiple victims across manufacturing, retail, and aviation sectors
22
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-44756CVSS 10affects SAP Extended Passport (EPP) Processing
A memory safety flaw in SAP Extended Passport Protocol processing allows an unauthenticated attacker to send a crafted network request and potentially achieve undefined behavior, code execution, or denial of service — a CVSS 10.0 with full CIA impact that demands immediate SAP patching.
2
CVE-2026-75650CVSS 10affects Adobe Commerce
Adobe Commerce is exposed to a template injection flaw enabling arbitrary code execution without any user interaction and with scope change, making this a critical supply-chain-level risk for any e-commerce operation running unpatched Commerce instances.
3
CVE-2026-86296CVSS 10PoCaffects DIR-822A
A stack-based buffer overflow in D-Link DIR-822A's udhcpcd component is remotely exploitable and already has a public proof-of-concept — defenders should treat this as near-weaponized and isolate or replace end-of-life devices immediately.
4
CVE-2026-58240CVSS 9.8affects SAP NetWeaver (Message Server)
SAP NetWeaver Message Server fails to validate the authenticity of internal application server components during registration, letting an unauthenticated network attacker register a rogue component and perform unauthorized actions across the SAP environment.
5
CVE-2026-86480CVSS 9.8affects Hub
JetBrains Hub before 2026.2.52442 allows an unauthenticated attacker to register a trusted service and elevate directly to superuser — organizations running Hub in internet-facing or multi-tenant environments face full administrative compromise.
6
CVE-2026-86478CVSS 9.8affects YouTrack
JetBrains YouTrack's Helpdesk module contains an improper authentication flaw that permits unauthenticated account takeover via a self-asserted email address, threatening project management and internal ticketing data across affected versions.
7
CVE-2026-7861CVSS 9.8affects CSM (Customer Service Management)
A deserialization of untrusted data vulnerability in Next4Biz CSM permits code injection, and the vendor did not respond to disclosure — absence of a vendor patch means defenders must apply compensating controls or restrict access to the affected platform immediately.
8
CVE-2026-18922CVSS 9.8affects Red Hat Directory Server 11.7 E4S for RHEL 8
A stale SASL identity bug in 389 Directory Server (Red Hat Directory Server 11.7 E4S) can allow an attacker to leverage a prior failed SASL PLAIN bind to authenticate as a privileged identity, including cn=Directory Manager, on a subsequent connection — a serious identity trust failure in LDAP infrastructure.
9
CVE-2026-76578CVSS 9.8affects Red Hat Enterprise Linux 10
A FreeIPA flaw allows an unauthenticated LDAP client to exploit a misconfigured OTP token ACI to create an attacker-controlled Kerberos principal, potentially leading to unauthorized access across Kerberos-authenticated services in Red Hat Enterprise Linux 10 environments.
10
CVE-2026-79697CVSS 9.4PoCaffects WISE-6610-CB
Multiple Advantech WISE-6610 IoT gateway variants are vulnerable to a critical flaw in the Basic Station Certificate-Deletion Handler; a public PoC exists and with a 3% EPSS the risk of targeted exploitation in OT/IoT environments is real — firmware updates should be prioritized for operational deployments.
Ransomware today

Ransomware activity targeting Brazil has been notably aggressive in recent days, with the group thegentlemen claiming victims across multiple sectors: Biotipo Jeans (retail), Zanini (manufacturing), Mutant, and Lider Aviacao (transportation). Dark Project separately claimed Alurwalls, a Brazilian manufacturer. Over the past 30 days, thegentlemen leads all groups with 9 recorded attacks, all in Brazil, followed by direwolf, krybit, and dragonforce — signaling a sustained, Brazil-focused campaign across diverse industries.

Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
Lider Aviacao BRthegentlemen · Transportation
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2kazu 2
Active groups & APTs

Several threat actor groups are being tracked as active or recently updated, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iran-linked blackshadow. While no confirmed new victims have been attributed to these groups in the current period, their continued monitoring status indicates maintained operational capability and potential for near-term activity.

Brazil focus

Brazil is under concentrated ransomware pressure, with recent victims spanning manufacturing (Zanini, Alurwalls, Engefitas), retail (Biotipo Jeans), transportation (Lider Aviacao), and other sectors (Mutant, ialegre.com, Oportunidados). The diversity of targeted sectors and the number of active groups — particularly thegentlemen and direwolf — suggests opportunistic but persistent threat actors with specific interest in Brazilian organizations, including mid-market and SMB targets that may have limited incident response capacity.

Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
Today’s recommendation: Security teams should prioritize patching SAP EPP (CVE-2026-44756) and NetWeaver (CVE-2026-58240), Adobe Commerce (CVE-2026-75650), and JetBrains Hub and YouTrack before end of week, given the unauthenticated attack vectors; for D-Link DIR-822A and Advantech WISE-6610 devices without vendor support, network segmentation or replacement is the safest path given available PoC code.
With critical unauthenticated flaws across enterprise platforms and active ransomware campaigns targeting diverse industries, now is the right time to validate whether your own attack surface is actually as patched and segmented as your asset inventory suggests.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share