Daily briefing · September 21, 2026
Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication Bypasses
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 21, 2026 registers as a calm day from an exploitation standpoint — no vulnerability crossed into active exploitation and no weaponized exploit was confirmed — but the CVE queue still carries ten critical entries demanding immediate review. Meanwhile, the ransomware picture around Brazil tells a sharply different story, with multiple groups claiming victims across manufacturing, retail, government, and technology sectors.
Today’s brief
- No CVEs in active exploitation today, but 19 critical severities were published — patch queues should not be ignored
- CVE-2026-94493 and CVE-2026-77521 both score CVSS 10.0: one exposes a POS terminal without authentication, the other allows unauthenticated remote code execution via AI assistant tooling
- Brazil-facing ransomware is loud: akira, play, emperador, and smaller groups claimed at least seven distinct Brazilian victims recently
- OpenStack Octavia users face two HAProxy config-injection flaws; Apache MINA 2.0.x and 2.1.x users were told a critical fix was applied in June 2026 — it was not
Critical highlights
1
The Gigatech PDV5701 point-of-sale terminal exposes its WebSocket service with no authentication whatsoever, scoring a perfect CVSS 10.0 with a public proof-of-concept already available. Any network-reachable attacker can interact with the service directly, making this a critical exposure for retail and hospitality environments that deploy this hardware.
2
MaxKB versions before 2.10.5-lts allow untrusted chat or ingested content to trigger shell command execution through an unsandboxed tool backend that skips human-approval checks — a CVSS 10.0 remote code execution path. Organizations running self-hosted MaxKB AI assistants with tool or MCP integrations should treat this as an emergency upgrade.
3
Any authenticated Ajenti user — regardless of privilege level — can invoke plugin installation, removal, or upgrade tasks that ultimately call pip with attacker-controlled package names and versions, enabling arbitrary code execution on the server. The CVSS 9.9 rating reflects how close to full compromise this privilege-escalation path sits on systems managed through Ajenti.
4
The Web to Print Online Designer WordPress plugin before 2.15.0 hands file-upload tokens to any unauthenticated visitor and accepts PHP files with no extension filtering, giving attackers a straightforward path to remote code execution on the web server. WordPress site operators should update immediately and audit for previously uploaded malicious files.
5
Mailu mail-server deployments configured with PROXY_AUTH_WHITELIST but without REAL_IP_HEADER trusted a client-controlled X-Forwarded-By header for proxy authentication, allowing unauthenticated attackers to impersonate any user. Affected helm-chart deployments up to version 2.7.2 should be updated to 2.7.3 and configuration reviewed.
6
A patch announced in June 2026 as fully fixing a Java deserialization filter bypass in Apache MINA (CVE-2026-47065) was only committed to the 2.2.x branch; MINA 2.0.29 and 2.1.13 artifacts were shipped without the resolveProxyClass() override, leaving those branches still vulnerable. Defenders relying on the published advisory to consider themselves protected on 2.0.x or 2.1.x are mistaken and should re-evaluate urgently.
7
Authenticated OpenStack project members with ownership of a TLS-enabled load balancer can inject arbitrary HAProxy configuration directives through unvalidated control characters in the tls_ciphers field of Octavia listeners and pools. The impact is constrained to deployments using the Amphora provider driver, but successful exploitation can subvert load-balancer behavior across the infrastructure.
8
A parallel Octavia flaw allows newlines embedded in L7 policy redirect_url and redirect_prefix fields to pass URL validation and persist into the HAProxy configuration, again enabling authenticated configuration injection. Both Octavia CVEs (this and CVE-2026-94572) should be remediated together by upgrading to OpenStack Octavia 18.0.1.
9
A write-what-where condition in the IOCTL handler of BioStar Temperature Monitor Utility's kernel driver (BS_HWMIO64_W10.sys) allows a local attacker to write arbitrary data to arbitrary memory addresses, a classic path to privilege escalation and kernel compromise. A public exploit exists, raising the urgency for environments where this utility is deployed.
10
BioStar BIOS Update Utility contains a similar write-what-where vulnerability in its kernel driver (BSMEM64_W10.sys), controllable via the PhysicalAddress and Size arguments in an IOCTL call. Both BioStar driver flaws require local access but are trivially dangerous in shared or multi-user environments where an attacker already holds a low-privileged session.
Ransomware today
Ransomware activity targeting Brazilian organizations has been particularly intense recently, with groups play, akira, arcusmedia, emperador, Panzer, and N0n collectively claiming at least seven distinct victims. Named targets include Metallco (manufacturing, play), Javep Chevrolet (retail, akira — listed twice suggesting multiple claim cycles), Cassias MG Government (government, emperador), Konnatus (professional services, N0n), Vetta (technology, akira), K3G Solutions Brazil (other, Panzer), and AKAZZO (arcusmedia). Over the past 30 days, thegentlemen leads activity with 8 incidents all in Brazil, followed by krybit, akira, and emperador.
Metallco BRplay · Manufacturing
Javep Chevrolet BRakira · Retail & E-Commerce
AKAZZO BRarcusmedia
Cassias MG Government BRemperador · Government & Defense
K3G Solutions Brazil BRPanzer · Other
Konnatus (usucapião legal services) BRN0n · Professional Services
Vetta BRakira · Technology
Javep Chevrolet BRakira · Retail & E-Commerce
thegentlemen 8krybit 3akira 3emperador 2Vexy Ransomware 2settra 2
Active groups & APTs
Several threat actor groups and APTs are currently tracked as active or recently updated, including handala, linkc, mogilevich, mosesstaff (Iran-linked), Elderwood (China-linked), and fulcrumsec. While no confirmed victims are attributed to these groups in the current data window, their monitored status indicates ongoing operational posture that defenders — particularly those in sectors historically targeted by Iranian and Chinese state-sponsored actors — should treat as a live threat indicator.
Brazil focus
Brazil stands out as the primary ransomware target in the current period, with victims spanning manufacturing (Metallco), retail and e-commerce (Javep Chevrolet), government (Cassias MG Government), professional services (Konnatus), technology (Vetta), and other sectors (K3G Solutions Brazil, AKAZZO). The diversity of sectors and the number of distinct ransomware groups involved suggests Brazil is being targeted opportunistically by multiple independent actors simultaneously, not by a single coordinated campaign.
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
AKAZZOarcusmedia
Cassias MG Governmentemperador · Government & Defense
Konnatus (usucapião legal services)N0n · Professional Services
Vettaakira · Technology
K3G Solutions BrazilPanzer · Other
Javep Chevroletakira · Retail & E-Commerce
Today’s recommendation: Prioritize patching CVE-2026-94493, CVE-2026-77521, and CVE-2026-82187 as the highest-risk entries with public proof-of-concept code; verify that Apache MINA deployments on the 2.0.x and 2.1.x branches have actually received the resolveProxyClass fix rather than trusting the June 2026 advisory at face value.
Given the breadth of critical vulnerabilities disclosed today and active ransomware pressure across multiple sectors, now is the right moment to validate whether your own attack surface is exposed to these classes of flaws before threat actors do it for you.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →