Daily briefing · July 16, 2026
Jupyter and WordPress Flaws Dominate a Calm but CVE-Heavy Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
July 16, 2026 saw no actively exploited vulnerabilities and no weaponized proof-of-concept code confirmed in the wild, making it a relatively calm day despite 263 new CVEs published, 33 of them critical. The spotlight falls on a trio of perfect-score flaws in Jupyter Enterprise Gateway and a cluster of authentication-bypass issues targeting WordPress plugins. While the threat landscape at the CVE level stays at a monitoring posture, ransomware activity against Brazilian organizations tells a very different story.
Today’s brief
- No CVEs in active exploitation (KEV) and no ready-made exploit modules confirmed today — monitoring posture applies.
- Three CVSS 10.0 flaws hit Jupyter Enterprise Gateway: YAML injection, SSTI, and root UID bypass — patch to 3.3.0 immediately.
- WordPress ecosystem takes multiple critical hits: authentication bypass in OTP Login, SAML SSO, and privilege escalation in Bricksforge.
- Brazil is under heavy ransomware pressure, with LockBit5 and RansomHouse hitting education, services, and technology sectors.
Critical highlights
1
A CVSS 10.0 YAML injection flaw in Jupyter Enterprise Gateway (before 3.3.0) allows attackers to manipulate untrusted KERNEL_XXX environment variables that are interpolated into Kubernetes manifests without proper escaping, potentially enabling full cluster compromise.
2
Also scoring CVSS 10.0, this Server-Side Template Injection vulnerability in Jupyter Enterprise Gateway allows Jinja2 template expressions embedded in KERNEL_XXX variables to be rendered server-side, enabling remote code execution in versions 2.0.0rc2 through 3.2.x.
3
HireFlow 1.2 and earlier ships with a hard-coded Flask secret key in its public source code, letting any unauthenticated attacker forge session cookies with admin privileges — a textbook credential bypass with zero barrier to exploitation.
4
Frogman's headless PBX component (before 1.6.2) allows a PERM_WRITE-privileged caller to inject arbitrary Asterisk dialplan configuration via unsanitized template parameters, potentially enabling unauthorized call routing or system-level abuse.
5
zrok's Python SDK (before 2.0.3) contains a Server-Side Request Forgery flaw where an attacker-controlled URL in the request path can override the configured proxy target, causing the backend to fetch and return arbitrary remote content.
6
The SAML Single Sign On – SSO Login WordPress plugin (through 5.4.3) is vulnerable to authentication bypass via Signature Algorithm Confusion, as it reads the signing algorithm from attacker-controlled SAML response data rather than enforcing a locally configured value.
7
CVE-2026-12492CVSS 9.8PoCaffects Happy Coders OTP Login for WooCommerce The Happy Coders OTP Login for WooCommerce plugin (before 2.8) skips actual OTP validation before authenticating users, allowing unauthenticated attackers to log in as any user including administrators — a proof-of-concept is already available, raising the urgency.
8
Bricksforge for WordPress (through 3.1.8.6) allows unauthenticated attackers to escalate to administrator by abusing improper validation of field IDs in the Pro Forms registration flow, enabling full site takeover without credentials.
9
A third critical flaw in Jupyter Enterprise Gateway allows bypassing the prohibited UID/GID 0 restriction through a specially crafted KERNEL_UID or KERNEL_GID value, potentially launching Kubernetes kernels as root and undermining cluster isolation.
10
Improper input validation in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows may allow an unauthenticated network attacker to perform account takeover — a high-impact flaw given Zoom's ubiquity in enterprise environments.
Ransomware today
Ransomware activity against Brazilian organizations has been intense in recent days, with LockBit5 claiming the largest share of victims including educational institutions sesi.org.br, senai.br, and cmc.com.br, alongside business services firms aditusbr.com, montaury.com.br, and consumer-facing drogales.com.br and sweetome.com. RansomHouse added Megawork to its list, while the group Settra claimed acilab.com in the technology sector. Over the past 30 days, LockBit3, LockBit5, and RansomHub have each exceeded 35 confirmed victims in Brazil alone, reflecting a sustained and focused campaign against the country.
cmc.com.br BRlockbit5 · Education
acilab.com BRsettra · Technology
Megawork BRransomhouse · Business Services
sesi.org.br BRlockbit5 · Education
senai.br BRlockbit5 · Education
aditusbr.com BRlockbit5 · Business Services
drogales.com.br BRlockbit5 · Consumer Services
montaury.com.br BRlockbit5 · Business Services
sweetome.com BRlockbit5 · Consumer Services
lockbit3 39lockbit5 36ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are currently tracked as active or recently updated, including Iranian-linked actors BlackShadow and CopyKittens, along with APT73, DragonForce, AgainstTheWest, and CoinbaseCartel. While no confirmed new victims are attributed to these groups in the current reporting window, their continued operational tracking signals maintained capability and potential for near-term activity.
Brazil focus
Brazil remains one of the most heavily targeted countries in the current ransomware landscape, with LockBit5 alone claiming multiple victims across education and business services sectors in recent days. The breadth of targets — ranging from professional training bodies like SENAI and SESI to small businesses and consumer services — indicates opportunistic as well as strategic targeting. Security teams in Brazilian organizations should treat ransomware exposure as an active and immediate threat, not a theoretical risk.
montaury.com.brlockbit5 · Business Services
drogales.com.brlockbit5 · Consumer Services
senai.brlockbit5 · Education
Megaworkransomhouse · Business Services
sesi.org.brlockbit5 · Education
aditusbr.comlockbit5 · Business Services
acilab.comsettra · Technology
cmc.com.brlockbit5 · Education
Today’s recommendation: Organizations running Jupyter Enterprise Gateway should upgrade to 3.3.0 immediately to address three separate CVSS 10.0 flaws; WordPress administrators should audit and patch the SAML SSO, OTP Login, and Bricksforge plugins without delay, prioritizing sites where unauthenticated registration or login is enabled.
Given the breadth of critical flaws published today — spanning cluster orchestration platforms, SSO systems, and widely deployed CMS plugins — now is the right moment to validate your own attack surface and confirm whether any of these components are reachable from untrusted networks.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →