Daily briefing · September 24, 2026
Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in Brazil
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 24, 2026 recorded no actively exploited vulnerabilities and no weaponized exploits confirmed in the wild, making it a calm day by threat-intelligence metrics. However, the vulnerability list published on this date includes two CVSS 10.0 flaws and several critical-severity issues that demand prompt attention from defenders. Meanwhile, ransomware activity targeting Brazilian organizations remained intense, with five newly confirmed victims across government, healthcare, manufacturing, and retail sectors.
Today’s brief
- Two CVSS 10.0 vulnerabilities in HFS2 enable unauthenticated RCE and arbitrary file access — proof-of-concept code already exists for both.
- A Visual Composer WordPress plugin flaw was weaponized on the same day it was disclosed, compressing the patch window to zero.
- Brazil is under sustained ransomware pressure: Receita Federal do Brasil, Amor Saúde, and Metallco among recently confirmed victims.
- No KEV additions today, but several critical flaws in industrial systems (DIAEnergie, Honeywell PD45) and the Linux kernel warrant immediate review.
Critical highlights
1
A prompt-injection flaw in the Decepticon autonomous red-team agent allows malicious ChatML tokens embedded in crawled web content to hijack LLM instructions under BYOK deployments. Organizations using this tool in red-team pipelines should upgrade to 1.1.17 immediately, as a compromised agent could be turned against its own operator's infrastructure.
2
HFS2 versions up to 2.4.0 expose arbitrary file read, write, append, and delete to unauthenticated attackers due to the macro dispatcher's missing authorization model combined with a path resolver that does not confine absolute paths. A proof-of-concept exists, making this a high-urgency patch for any team running HFS2-based file sharing.
3
A template injection vulnerability in HFS2's multipart upload handler lets unauthenticated attackers achieve remote code execution by embedding malicious template syntax inside a crafted filename. With a PoC already public, exposure of HFS2 to untrusted networks should be treated as a critical risk requiring immediate remediation or isolation.
4
An authenticated organization member with only service:read permission in Dokploy can inject shell metacharacters via the repoPath parameter, escalating to arbitrary command execution on the host. Teams running self-hosted PaaS environments should patch to version 0.29.13 or later without delay.
5
Velociraptor's failure to restrict the internal compiled_collector_args field from the user API allows an investigator-level user to inject arbitrary VQL statements into a hunt, potentially redirecting endpoint data collection across an entire fleet. This is especially dangerous in multi-tenant or large SOC deployments where role separation is a core security control.
6
CVE-2026-12227CVSS 9.8PoCsame dayaffects Visual Composer Website Builder The Visual Composer Website Builder WordPress plugin is vulnerable to unauthenticated Local File Inclusion through the vcv-template parameter, enabling PHP code execution and full access control bypass. The exploit was weaponized on the same day as disclosure, meaning any unpatched WordPress site running versions up to 45.16.0 should be considered at immediate risk.
7
An authentication bypass vulnerability in DIAEnergie (before 1.11.00.022) allows attackers to circumvent login controls entirely on an industrial energy management platform. Industrial environments running this software should treat exposure to any untrusted network segment as unacceptable until patched.
8
The Honeywell PD45 Industrial Printer web management interface allows unauthenticated arbitrary file upload leading to remote code execution, a particularly severe risk in OT environments where printers may be implicitly trusted on the network. Physical network segmentation should be verified immediately while awaiting vendor patch availability.
9
An integer underflow in the Linux kernel's RDMA/rtrs-srv subsystem can be triggered by a malicious RDMA client sending a crafted message, potentially leading to memory corruption or denial of service. Systems using RDMA networking in high-performance or cloud environments should monitor for kernel updates addressing this flaw.
10
A use-of-uninitialized-data flaw in the Linux kernel's SUNRPC GSS authentication path can allow early decoding errors to expose stale credential data from a prior request, potentially leaking sensitive authentication context across NFS clients. Environments relying heavily on Kerberos-authenticated NFS shares should prioritize kernel patching.
Ransomware today
Ransomware activity targeting Brazil remains highly concentrated: recently confirmed victims include Receita Federal do Brasil (attributed to emperador), Amor Saúde (lockbit5), Grupo Caberj (incransom), Metallco (play), and Javep Chevrolet (akira), spanning government, healthcare, manufacturing, and retail sectors. Among the most active groups over the past 30 days, thegentlemen leads with eight attacks — all directed at Brazilian targets — followed by akira, krybit, and emperador, each with three Brazil-focused incidents. The breadth of sectors and the volume of Brazil-specific hits signal that the country is being systematically targeted rather than caught in opportunistic crossfire.
Grupo Caberj BRincransom · Manufacturing
RECEITA FEDERAL DO BRASIL BRemperador · Government & Defense
amorsaude.com.br BRlockbit5 · Healthcare
Metallco BRplay · Manufacturing
Javep Chevrolet BRakira · Retail & E-Commerce
thegentlemen 8akira 3krybit 3emperador 3Vexy Ransomware 2settra 2
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated in threat intelligence feeds, including handala, linkc, mogilevich, mosesstaff (Iran), Elderwood (China), and fulcrumsec. No confirmed victims have been publicly attributed to these groups in the current period, but their active status indicates ongoing reconnaissance or staging activity that defenders should monitor closely. The presence of a China-linked group (Elderwood) and an Iran-linked group (mosesstaff) alongside financially motivated actors reflects the mixed threat landscape currently observed.
Brazil focus
Brazil is experiencing an unusually concentrated wave of ransomware incidents, with eight victims recently identified in addition to the five confirmed in the latest reporting window. High-profile targets include a federal tax authority (Receita Federal do Brasil) and a healthcare platform (amorsaude.com.br), alongside municipal government and manufacturing victims — indicating that no sector or institution size is out of scope for current threat actors operating in the region. Defenders in Brazilian organizations should treat the current environment as elevated-risk and prioritize asset visibility, backup integrity, and network segmentation reviews.
Grupo Caberjincransom · Manufacturing
amorsaude.com.brlockbit5 · Healthcare
RECEITA FEDERAL DO BRASILemperador · Government & Defense
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
K3G Solutions BrazilPanzer · Other
Today’s recommendation: Security teams should prioritize patching HFS2 (both CVSS 10.0 flaws with public PoCs) and the Visual Composer WordPress plugin (weaponized on day zero), while immediately assessing network exposure of DIAEnergie and Honeywell PD45 industrial systems pending vendor patches. Linux kernel updates addressing the RDMA and SUNRPC flaws should be scheduled promptly for RDMA-enabled and NFS-heavy environments.
Even on a calm vulnerability day, the gap between disclosure and exploitation can be measured in hours — validating your actual exposure across all affected asset classes is the only reliable way to know whether today's critical CVEs represent a theoretical risk or an active one for your environment.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →