Daily briefing · September 10, 2026

Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware Surge

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 10, 2026 registered no active exploitations or weaponized vulnerabilities, placing the day firmly in calm territory despite a substantial batch of 379 new CVEs — 56 of them rated critical. The standout concern is the volume and severity of newly published flaws, including a perfect CVSS 10.0 in a widely deployed WordPress plugin, several critical Plesk and Apache flaws, and a default-credentials issue in IBM ContextForge. With no confirmed in-the-wild exploitation yet, defenders have a narrow window to prioritize patching before threat actors act.

Today’s brief
  • No active exploitation or weaponized exploits recorded today — calm verdict, but the patch queue is heavy
  • CVE-2026-77770 scores a perfect 10.0 against the miniOrange 2FA WordPress plugin, enabling any unauthenticated visitor to delete arbitrary site options and lock out all administrators
  • Critical RCE flaws in Forgejo, arbitrary file-write and privilege escalation in Plesk, session hijacking in Apache ActiveMQ Artemis, and code injection in Apache Camel K demand urgent attention
  • Brazil is under sustained ransomware pressure, with thegentlemen and Vexy Ransomware among the most active groups hitting Brazilian organizations across multiple sectors
56
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-77770CVSS 10PoCaffects miniOrange 2FA
A CVSS 10.0 unauthenticated option-deletion flaw in the miniOrange 2FA WordPress plugin (before 6.3.1 / 19.3) allows any visitor to wipe arbitrary WordPress options, effectively locking every administrator out of the dashboard or disabling 2FA site-wide — a proof of concept is already public, making exploitation trivially accessible.
2
CVE-2026-89094CVSS 9.9affects Forgejo
Forgejo before 16.0.4 allows remote code execution through malicious template repositories, as template expansion on files within .forgejo/template is improperly handled; any attacker who can push a crafted repository to an exposed instance can achieve RCE.
3
CVE-2026-68487CVSS 9.9affects Plesk
A path traversal vulnerability in Plesk's Backup Manager permits an authenticated customer to write arbitrary files as root, effectively handing any tenant on a shared Plesk host a route to full server compromise.
4
CVE-2026-68488CVSS 9.9affects Plesk
A TOCTOU race condition in Plesk enables local privilege escalation to root via insecure symlink following, allowing an attacker who can run local code to take ownership of arbitrary files and directories — particularly dangerous in multi-tenant hosting environments.
5
CVE-2026-7188CVSS 9.8affects Access Control System
A classic SQL injection vulnerability in Armiya's Access Control System (before Version 2) can be exploited without elevated privileges, potentially exposing access logs, credentials, and physical security data to a remote attacker.
6
CVE-2026-57967CVSS 9.8affects Apache ActiveMQ Artemis
Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 and 2.50.0 through 2.56.0 are vulnerable to unauthenticated session hijacking via a crafted CORE protocol packet, allowing an attacker to steal and resume any existing authenticated session without credentials — upgrade to 2.57.0 immediately.
7
CVE-2026-88278CVSS 9.8affects GV-LPCLPC2011/2211
GeoVision GV-LPC2211 V1.13 ONVIF implementation fails to enforce nonce reuse or token freshness checks, meaning a captured authentication token can be replayed indefinitely to perform unauthorized camera operations — a critical risk for physical security deployments.
8
CVE-2026-80351CVSS 9.8affects Apache Camel K
An eval injection vulnerability in Apache Camel K allows tenant-controlled Maven repository content to influence code execution inside the operator pod, potentially letting a malicious tenant run arbitrary code with operator-level Kubernetes privileges.
9
CVE-2026-80352CVSS 9.8affects Apache Camel K
A YAML injection flaw in Apache Camel K custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, enabling unauthorized resource creation with the full privileges of the Camel K operator — a significant supply-chain and multi-tenant risk.
10
CVE-2026-78573CVSS 9.8affects ContextForge MCP Gateway
IBM ContextForge MCP Gateway 1.0.0–1.0.7 ships with default credentials that grant remote administrative access, an immediately exploitable condition requiring no prior knowledge of the target environment beyond network reachability.
Ransomware today

Ransomware activity targeting Brazilian organizations remains notably elevated. Recently identified victims include amorsaude.com.br (Healthcare, attributed to lockbit5), Logar Network Solutions and Engefitas (attributed to Vexy Ransomware), and Biotipo Jeans, Zanini, Mutant, and Lider Aviacao (all claimed by thegentlemen), alongside Alurwalls in manufacturing (Dark Project). Among groups active over the past 30 days, thegentlemen leads with 9 recorded victims — all in Brazil — followed by krybit (3), dragonforce (2), direwolf (2), and Vexy Ransomware (2), underscoring a sustained and concentrated campaign against Brazilian targets.

amorsaude.com.br BRlockbit5 · Healthcare
Logar Network Solutions BRVexy Ransomware · Technology
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
thegentlemen 9krybit 3direwolf 2dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs

Several threat actor groups are being monitored for renewed or emerging activity: dragonforce, fulcrumsec, funksec, linkc, spacebears, and Iran-linked blackshadow are all flagged as active or recently updated, though no new confirmed victims have been attributed to them in this reporting window. Their presence on threat intelligence feeds warrants continued monitoring, particularly given dragonforce's recent victim count in Brazil.

Brazil focus

Brazil continues to face disproportionate ransomware pressure relative to the global calm observed in vulnerability exploitation today. The concentration of thegentlemen victims across manufacturing, retail, transportation, and other sectors suggests the group is running a broad, opportunistic campaign rather than targeting a single industry. Organizations in these sectors should treat patching and credential hygiene as immediate priorities.

amorsaude.com.brlockbit5 · Healthcare
Logar Network SolutionsVexy Ransomware · Technology
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
Today’s recommendation: Prioritize patching CVE-2026-77770 on any WordPress instance running miniOrange 2FA, and urgently review Plesk, Apache ActiveMQ Artemis, and Apache Camel K deployments for the critical flaws disclosed today — in parallel, verify that no internet-facing systems rely on default credentials, particularly IBM ContextForge MCP Gateway.
Even on a calm day with no confirmed exploitations, the sheer number of newly disclosed critical flaws is a reminder that validating your own attack surface — before adversaries do — is the only reliable way to know whether your organization is exposed.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share