Daily briefing · September 10, 2026
Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware Surge
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 10, 2026 registered no active exploitations or weaponized vulnerabilities, placing the day firmly in calm territory despite a substantial batch of 379 new CVEs — 56 of them rated critical. The standout concern is the volume and severity of newly published flaws, including a perfect CVSS 10.0 in a widely deployed WordPress plugin, several critical Plesk and Apache flaws, and a default-credentials issue in IBM ContextForge. With no confirmed in-the-wild exploitation yet, defenders have a narrow window to prioritize patching before threat actors act.
Today’s brief
- No active exploitation or weaponized exploits recorded today — calm verdict, but the patch queue is heavy
- CVE-2026-77770 scores a perfect 10.0 against the miniOrange 2FA WordPress plugin, enabling any unauthenticated visitor to delete arbitrary site options and lock out all administrators
- Critical RCE flaws in Forgejo, arbitrary file-write and privilege escalation in Plesk, session hijacking in Apache ActiveMQ Artemis, and code injection in Apache Camel K demand urgent attention
- Brazil is under sustained ransomware pressure, with thegentlemen and Vexy Ransomware among the most active groups hitting Brazilian organizations across multiple sectors
Critical highlights
1
A CVSS 10.0 unauthenticated option-deletion flaw in the miniOrange 2FA WordPress plugin (before 6.3.1 / 19.3) allows any visitor to wipe arbitrary WordPress options, effectively locking every administrator out of the dashboard or disabling 2FA site-wide — a proof of concept is already public, making exploitation trivially accessible.
2
Forgejo before 16.0.4 allows remote code execution through malicious template repositories, as template expansion on files within .forgejo/template is improperly handled; any attacker who can push a crafted repository to an exposed instance can achieve RCE.
3
A path traversal vulnerability in Plesk's Backup Manager permits an authenticated customer to write arbitrary files as root, effectively handing any tenant on a shared Plesk host a route to full server compromise.
4
A TOCTOU race condition in Plesk enables local privilege escalation to root via insecure symlink following, allowing an attacker who can run local code to take ownership of arbitrary files and directories — particularly dangerous in multi-tenant hosting environments.
5
A classic SQL injection vulnerability in Armiya's Access Control System (before Version 2) can be exploited without elevated privileges, potentially exposing access logs, credentials, and physical security data to a remote attacker.
6
Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 and 2.50.0 through 2.56.0 are vulnerable to unauthenticated session hijacking via a crafted CORE protocol packet, allowing an attacker to steal and resume any existing authenticated session without credentials — upgrade to 2.57.0 immediately.
7
GeoVision GV-LPC2211 V1.13 ONVIF implementation fails to enforce nonce reuse or token freshness checks, meaning a captured authentication token can be replayed indefinitely to perform unauthorized camera operations — a critical risk for physical security deployments.
8
An eval injection vulnerability in Apache Camel K allows tenant-controlled Maven repository content to influence code execution inside the operator pod, potentially letting a malicious tenant run arbitrary code with operator-level Kubernetes privileges.
9
A YAML injection flaw in Apache Camel K custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, enabling unauthorized resource creation with the full privileges of the Camel K operator — a significant supply-chain and multi-tenant risk.
10
IBM ContextForge MCP Gateway 1.0.0–1.0.7 ships with default credentials that grant remote administrative access, an immediately exploitable condition requiring no prior knowledge of the target environment beyond network reachability.
Ransomware today
Ransomware activity targeting Brazilian organizations remains notably elevated. Recently identified victims include amorsaude.com.br (Healthcare, attributed to lockbit5), Logar Network Solutions and Engefitas (attributed to Vexy Ransomware), and Biotipo Jeans, Zanini, Mutant, and Lider Aviacao (all claimed by thegentlemen), alongside Alurwalls in manufacturing (Dark Project). Among groups active over the past 30 days, thegentlemen leads with 9 recorded victims — all in Brazil — followed by krybit (3), dragonforce (2), direwolf (2), and Vexy Ransomware (2), underscoring a sustained and concentrated campaign against Brazilian targets.
amorsaude.com.br BRlockbit5 · Healthcare
Logar Network Solutions BRVexy Ransomware · Technology
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
thegentlemen 9krybit 3direwolf 2dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs
Several threat actor groups are being monitored for renewed or emerging activity: dragonforce, fulcrumsec, funksec, linkc, spacebears, and Iran-linked blackshadow are all flagged as active or recently updated, though no new confirmed victims have been attributed to them in this reporting window. Their presence on threat intelligence feeds warrants continued monitoring, particularly given dragonforce's recent victim count in Brazil.
Brazil focus
Brazil continues to face disproportionate ransomware pressure relative to the global calm observed in vulnerability exploitation today. The concentration of thegentlemen victims across manufacturing, retail, transportation, and other sectors suggests the group is running a broad, opportunistic campaign rather than targeting a single industry. Organizations in these sectors should treat patching and credential hygiene as immediate priorities.
amorsaude.com.brlockbit5 · Healthcare
Logar Network SolutionsVexy Ransomware · Technology
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
Today’s recommendation: Prioritize patching CVE-2026-77770 on any WordPress instance running miniOrange 2FA, and urgently review Plesk, Apache ActiveMQ Artemis, and Apache Camel K deployments for the critical flaws disclosed today — in parallel, verify that no internet-facing systems rely on default credentials, particularly IBM ContextForge MCP Gateway.
Even on a calm day with no confirmed exploitations, the sheer number of newly disclosed critical flaws is a reminder that validating your own attack surface — before adversaries do — is the only reliable way to know whether your organization is exposed.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →