Daily briefing · July 8, 2026
WordPress and CoreWCF Under Pressure: Active Exploitation Detected on July 8, 2026
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
July 8, 2026 brings a wave of 335 new vulnerabilities, including 18 rated critical, with one standing out as already observed in active exploitation by VulnCheck ahead of any official CISA confirmation — a WordPress plugin flaw enabling unauthenticated file uploads. The day's verdict is CAUTION: no fully weaponized exploits confirmed, but the early exploitation signal on Blocksy Companion and a CVSS 10.0 authentication bypass in CoreWCF demand immediate defensive attention. Defenders should treat the VulnCheck-flagged CVE as actively weaponized in practice, regardless of official KEV status.
Today’s brief
- CVE-2026-58480 (Blocksy Companion, WordPress): unauthenticated file upload already observed in exploitation by VulnCheck — patch or disable now.
- CVE-2026-54782 (CoreWCF): CVSS 10.0 SAML token validation bypass allows full identity impersonation without authentication — maximum severity.
- CVE-2026-12153 (WP Learn Manager) and CVE-2026-9701 (Eventer): two additional critical WordPress plugin flaws enabling unauthorized plugin installs and account takeover.
- Brazil-focused ransomware activity is intensifying, with victims claimed by qilin, incransom, and Doommageddon across multiple sectors.
Critical highlights
1
VulnCheck has observed exploitation of this flaw in Blocksy Companion Pro (WordPress, before 2.1.47) before CISA's official acknowledgment — a strong early warning signal. Unauthenticated attackers can bypass extension validation via a double-extension trick in the Custom Fonts/Advanced Reviews feature to upload executable files, enabling remote code execution on any exposed WordPress site.
2
A CVSS 10.0 critical flaw in CoreWCF (before 1.8.1/1.9.1) allows an unauthenticated remote attacker to completely bypass SAML 1.1 and 2.0 token validation when federated bindings are used, effectively impersonating any principal the trusted STS can issue — this means full identity takeover with zero credentials on vulnerable .NET Core services.
3
WP Learn Manager (WordPress, up to 1.1.8) fails to verify user authorization, allowing completely unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository — a trivial path to full site compromise via a malicious or vulnerable third-party plugin.
4
An improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (releases 2020 through 2026) could grant an attacker privileged server access — particularly concerning in manufacturing and industrial environments where this MES platform is commonly deployed.
5
The Eventer WordPress plugin (up to 4.4.2) stores password reset keys in plaintext in the wp_usermeta table, enabling any user with database read access or exploiting a secondary SQLi to trivially reset any account's password and take over the site.
6
Fluentd (before 1.19.3) allows path traversal through insufficient validation of the ${tag} placeholder in file output plugin configurations, enabling attackers who can control log tag values to write files to arbitrary paths on the server — a serious risk in centralized logging pipelines.
7
A classic SQL injection in Mediküm Web (Webbeyaz) through version 08072026 allows arbitrary database manipulation — compounded by the fact that the vendor has confirmed the product is no longer supported, meaning no patch will be issued and exposed instances must be isolated or decommissioned immediately.
8
Authenticated low-privilege users of the Snowflake Snowpark Python SDK (before 1.53.0) can escalate privileges by injecting SQL payloads through specially crafted column names in the DataFrameReader.dbapi() API — a privilege escalation path that could expose sensitive data warehousing infrastructure.
9
A cross-site scripting vulnerability in Microsoft Dynamics 365 Customer Voice enables network-based spoofing attacks against unauthenticated targets — a risk for organizations relying on this platform for customer feedback and survey workflows, where session or credential theft via crafted links is plausible.
10
JupyterLab Git (0.30.0b3 to 0.53.x) passes Git filenames directly to innerHTML when rendering renamed files in commit history, meaning a maliciously crafted filename in a repository can execute arbitrary JavaScript in any victim's browser viewing the Git History tab — a stored XSS risk in widely used data science environments.
Ransomware today
Ransomware activity targeting Brazilian organizations remains at elevated levels. Recently claimed victims include S.J. Louis (qilin), tecnocurva.com.br in the Technology sector (incransom), and Francisco Imóveis in Consumer Services (Doommageddon). Over the past 30 days, lockbit3, ransomhub, and lockbit5 have been the most prolific groups, with lockbit3 accounting for 39 victims in Brazil alone.
S.J. Louis BRqilin
tecnocurva.com.br BRincransom · Technology
Francisco Imóveis BRDoommageddon · Consumer Services
lockbit3 39ransomhub 35lockbit5 26thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actors are currently being tracked with updated activity profiles, including againstthewest, apt73, dragonforce, fulcrumsec, coinbasecartel, and Iran-linked blackshadow. While no new confirmed victims are attributed to these groups in this cycle, their active monitoring status suggests operational readiness, and apt73 has been linked to a recent victim in Brazil (flazio.com).
Brazil focus
Brazil continues to be a heavily targeted country in the current ransomware landscape. Recent victims span multiple sectors: S.J. Louis (qilin), tecnocurva.com.br (incransom, Technology), Francisco Imóveis (Doommageddon, Consumer Services), redeplastrs.com.br (Blackfield, Manufacturing), Service IT (worldleaks, Business Services), tambasa.com and carvalima.com.br (both incransom, Business Services). The concentration of incransom activity against Brazilian targets is particularly notable.
S.J. Louisqilin
tecnocurva.com.brincransom · Technology
Francisco ImóveisDoommageddon · Consumer Services
redeplastrs.com.brBlackfield · Manufacturing
flazio.comapt73 · Technology
Service ITworldleaks · Business Services
tambasa.comincransom
carvalima.com.brincransom · Business Services
Today’s recommendation: Immediately patch or disable the Blocksy Companion Pro plugin on all WordPress installations given active exploitation observed in the wild, and prioritize updating CoreWCF to 1.8.1 or 1.9.1 in any .NET Core service using federated SAML bindings. Organizations running other affected WordPress plugins (WP Learn Manager, Eventer) and Fluentd should also treat those updates as urgent given the unauthenticated attack surface exposed.
The breadth of today's critical vulnerabilities — spanning CMS plugins, logging pipelines, data platforms, and enterprise identity — underscores why validating your actual exposed attack surface, rather than relying on vendor advisory timelines alone, is essential to understanding real organizational risk.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →