Daily briefing · September 7, 2026
22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazil
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 7, 2026 registers as a calm day from an exploitation standpoint — no vulnerabilities were weaponized, no active exploitation confirmed, and no VulnCheck early signals — but the volume of critical disclosures remains substantial, with 22 critical CVEs published in a single day. The top entries span SAP, Adobe Commerce, D-Link, JetBrains, and Red Hat, several carrying perfect CVSS scores. While no immediate fire drills are required, the breadth of affected enterprise and SMB products demands prompt patch triage.
Today’s brief
- No active exploitation or weaponized exploits recorded today — patch window exists but is narrow
- Two CVSS 10.0 SAP flaws and a CVE-2026-75650 Adobe Commerce RCE lead the day's critical disclosures
- JetBrains Hub and YouTrack hit with unauthenticated privilege escalation and account takeover bugs
- Brazil faces intense ransomware pressure: thegentlemen group claimed multiple victims across manufacturing, retail, and aviation sectors
Critical highlights
1
A memory safety flaw in SAP Extended Passport Protocol processing allows an unauthenticated attacker to send a crafted network request and potentially achieve undefined behavior, code execution, or denial of service — a CVSS 10.0 with full CIA impact that demands immediate SAP patching.
2
Adobe Commerce is exposed to a template injection flaw enabling arbitrary code execution without any user interaction and with scope change, making this a critical supply-chain-level risk for any e-commerce operation running unpatched Commerce instances.
3
A stack-based buffer overflow in D-Link DIR-822A's udhcpcd component is remotely exploitable and already has a public proof-of-concept — defenders should treat this as near-weaponized and isolate or replace end-of-life devices immediately.
4
SAP NetWeaver Message Server fails to validate the authenticity of internal application server components during registration, letting an unauthenticated network attacker register a rogue component and perform unauthorized actions across the SAP environment.
5
JetBrains Hub before 2026.2.52442 allows an unauthenticated attacker to register a trusted service and elevate directly to superuser — organizations running Hub in internet-facing or multi-tenant environments face full administrative compromise.
6
JetBrains YouTrack's Helpdesk module contains an improper authentication flaw that permits unauthenticated account takeover via a self-asserted email address, threatening project management and internal ticketing data across affected versions.
7
A deserialization of untrusted data vulnerability in Next4Biz CSM permits code injection, and the vendor did not respond to disclosure — absence of a vendor patch means defenders must apply compensating controls or restrict access to the affected platform immediately.
8
CVE-2026-18922CVSS 9.8affects Red Hat Directory Server 11.7 E4S for RHEL 8 A stale SASL identity bug in 389 Directory Server (Red Hat Directory Server 11.7 E4S) can allow an attacker to leverage a prior failed SASL PLAIN bind to authenticate as a privileged identity, including cn=Directory Manager, on a subsequent connection — a serious identity trust failure in LDAP infrastructure.
9
A FreeIPA flaw allows an unauthenticated LDAP client to exploit a misconfigured OTP token ACI to create an attacker-controlled Kerberos principal, potentially leading to unauthorized access across Kerberos-authenticated services in Red Hat Enterprise Linux 10 environments.
10
Multiple Advantech WISE-6610 IoT gateway variants are vulnerable to a critical flaw in the Basic Station Certificate-Deletion Handler; a public PoC exists and with a 3% EPSS the risk of targeted exploitation in OT/IoT environments is real — firmware updates should be prioritized for operational deployments.
Ransomware today
Ransomware activity targeting Brazil has been notably aggressive in recent days, with the group thegentlemen claiming victims across multiple sectors: Biotipo Jeans (retail), Zanini (manufacturing), Mutant, and Lider Aviacao (transportation). Dark Project separately claimed Alurwalls, a Brazilian manufacturer. Over the past 30 days, thegentlemen leads all groups with 9 recorded attacks, all in Brazil, followed by direwolf, krybit, and dragonforce — signaling a sustained, Brazil-focused campaign across diverse industries.
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
Lider Aviacao BRthegentlemen · Transportation
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2kazu 2
Active groups & APTs
Several threat actor groups are being tracked as active or recently updated, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iran-linked blackshadow. While no confirmed new victims have been attributed to these groups in the current period, their continued monitoring status indicates maintained operational capability and potential for near-term activity.
Brazil focus
Brazil is under concentrated ransomware pressure, with recent victims spanning manufacturing (Zanini, Alurwalls, Engefitas), retail (Biotipo Jeans), transportation (Lider Aviacao), and other sectors (Mutant, ialegre.com, Oportunidados). The diversity of targeted sectors and the number of active groups — particularly thegentlemen and direwolf — suggests opportunistic but persistent threat actors with specific interest in Brazilian organizations, including mid-market and SMB targets that may have limited incident response capacity.
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
Today’s recommendation: Security teams should prioritize patching SAP EPP (CVE-2026-44756) and NetWeaver (CVE-2026-58240), Adobe Commerce (CVE-2026-75650), and JetBrains Hub and YouTrack before end of week, given the unauthenticated attack vectors; for D-Link DIR-822A and Advantech WISE-6610 devices without vendor support, network segmentation or replacement is the safest path given available PoC code.
With critical unauthenticated flaws across enterprise platforms and active ransomware campaigns targeting diverse industries, now is the right time to validate whether your own attack surface is actually as patched and segmented as your asset inventory suggests.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →