ColdFusion · Linux kernel KVM hypervisor · BeyondTrust Remote Support and Privileged Remote Access
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-07-07 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
Active exploitation of Adobe ColdFusion CVE-2026-48316 (CVSS 10.0) has been confirmed, making it the most urgent item today. Three critical pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access were published, posing significant risk to enterprise privileged access infrastructure. A 16-year-old Linux KVM guest-to-host escape flaw (CVE-2026-53359, “Januscape”) has a public proof-of-concept. An Iran-linked threat actor is deploying a new C2 framework against Israeli IT and government targets. Multiple Apache Camel components received critical patches from BSI.
CRITICAL VULNERABILITIES
NEW
CVE-2026-48316 (Adobe ColdFusion)
- Affected products: ColdFusion 2025.9, 2023.20 and earlier
- Severity: CVSS 10.0
- EPSS: 0.00 (newly published; exploitation already confirmed in the wild)
- Technical detail: An improper input validation flaw allows unauthenticated remote code execution in the context of the ColdFusion service account. The vulnerability is network-exploitable with no authentication or user interaction required. ColdFusion is widely deployed in enterprise web application environments, including government and financial sector deployments in Europe. KEVIntel has confirmed active exploitation in attacks as of 2026-07-06.
- Exploitation status: Actively exploited in the wild. Treat as emergency priority.
- Remediation: Apply Adobe’s patches to ColdFusion 2025 and 2023 immediately. If patching cannot be completed within hours, isolate ColdFusion servers from the internet and restrict to internal networks. Review web server logs for anomalous POST requests and unexpected process spawning from the ColdFusion service. Note: a separate ColdFusion cluster (CVE-2026-48283 et al.) was reported previously; this is a distinct new CVE confirmed exploited today.
CVE-2026-53359 (Linux KVM — “Januscape”)
- Affected products: Linux kernel KVM hypervisor, Intel and AMD x86 systems
- Severity: Not yet assigned; researcher-reported use-after-free
- EPSS: Not yet scored
- Technical detail: A use-after-free vulnerability in the KVM shadow MMU code, shared across Intel and AMD x86 implementations, can be triggered from within a guest virtual machine to corrupt host kernel shadow-page state. A public proof-of-concept currently causes a host kernel panic; the researcher states a separate, unreleased exploit achieves full guest-to-host escape. The flaw has existed for approximately 16 years. Any environment running untrusted or multi-tenant guest VMs — including cloud infrastructure, VDI deployments, and shared hosting — is at elevated risk.
- Exploitation status: Public PoC available (panic-level). Full escape exploit not yet public. High urgency given PoC availability and hypervisor attack surface.
- Remediation: Monitor Linux kernel security channels and distribution vendor advisories (Red Hat, Ubuntu, SUSE, Debian) for patches. Apply kernel updates as soon as available. As an interim measure, restrict guest VM privileges and audit which workloads run in shared hypervisor environments. Do not run untrusted code in guest VMs on unpatched hosts.
CVE-2026-40138 / CVE-2026-40139 (BeyondTrust Remote Support and Privileged Remote Access)
- Affected products: BeyondTrust Remote Support and Privileged Remote Access, versions prior to 25.3.3 and 26.2.1
- Severity: CVSS 9.2 (both CVEs)
- EPSS: 0.00 (newly published)
- Technical detail: Two critical pre-authentication vulnerabilities exist in the authentication subsystem. CVE-2026-40138 involves improper validation of authentication data, potentially allowing a network-adjacent unauthenticated attacker to bypass authentication. CVE-2026-40139 involves improper processing of authentication requests with a similar pre-auth bypass impact. A third related flaw, CVE-2026-40140 (CVSS 8.7), affects the network communication subsystem. BeyondTrust products are widely deployed as privileged access management and remote support infrastructure in enterprise environments. Compromise of these systems provides direct access to privileged sessions and managed endpoints.
- Exploitation status: No confirmed exploitation. Pre-authentication attack surface and enterprise deployment prevalence make this a high-priority patch.
- Remediation: Upgrade BeyondTrust Remote Support and Privileged Remote Access to version 25.3.3 or 26.2.1 or later. Restrict management interfaces to trusted networks. Review access logs for anomalous authentication attempts pending patching.
CVE-2026-20896 (Gitea Docker)
- STATUS CHANGE: Active exploitation probing confirmed by Sysdig, 13 days after disclosure. Threat actors are observed attempting exploitation of this CVSS 9.8 authentication bypass (trusting the X-WEBAUTH-USER header from any source IP). Previously reported as patch-required; now confirmed under active attack.
- Update: Treat as actively exploited. Verify upgrade to Gitea 1.26.3 is complete on all instances. Check for unauthorized administrative account creation in Gitea audit logs.
ONGOING
- CVE-2026-59509 (cve-search): restrict /fetch_cve_data endpoint; patch pending.
- CVE-2026-59510 (ail-framework): update to patched commit; restrict to internal networks.
- CVE-2026-48283 et al. (Adobe ColdFusion, prior cluster): patch if not yet applied.
- CVE-2026-46242 (Linux Kernel “Bad Epoll”): apply distribution vendor patches.
- CVE-2026-45659 (Microsoft SharePoint): CISA KEV deadline passed; verify patch applied.
- CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
- CVE-2026-48558 (SimpleHelp): CISA KEV deadline passed; hunt for Djinn Stealer indicators.
- CVE-2026-46817 (Oracle E-Business Suite): actively exploited; patch immediately.
- CVE-2026-10109 (IBM Db2): pre-auth RCE; patch and restrict port 50000.
- BlueHammer (Windows Defender privilege escalation): actively exploited; verify patch applied.
EUROPEAN ADVISORIES
BSI published a new advisory (WID-SEC-2026-2203) covering multiple critical and high-severity vulnerabilities across Apache Camel components, including CVE-2026-56140 (AWS SNS, CVSS 9.8), CVE-2026-46456 (AWS2-SQS, CVSS 9.8), CVE-2026-48204 (MongoDB GridFS, CVSS 9.8), CVE-2026-46454 (Cometd, CVSS 9.8), CVE-2026-43867 and CVE-2026-46590 (PQC deserialization, CVSS 9.8/8.8), CVE-2026-48203 (Solr, SSRF/injection, CVSS 9.1), CVE-2026-48205 (DNS, SSRF, CVSS 9.1), and CVE-2026-40047 (Docling argument injection, CVSS 9.1). The common thread is insufficient header filtering and input validation across multiple Camel components, allowing header injection, SSRF, and in some cases remote code execution. Affected versions span Camel 4.0.0 through pre-4.14.8, 4.15.0 through pre-4.18.3, and 4.19.0 through pre-4.21.0. Upgrade to Apache Camel 4.14.8, 4.18.3, or 4.21.0 as appropriate. Two earlier Apache Camel advisories (WID-SEC-2026-1271, WID-SEC-2026-0445) were also updated.
BSI published a new advisory (WID-SEC-2026-2205) for n8n covering a code execution vulnerability that can lead to data exfiltration, service disruption, or full system compromise. This aligns with the previously reported CVE-2025-71380 (Execute Command node). Restrict the Execute Command node and enforce MFA on all n8n instances.
BSI published a new advisory (WID-SEC-2026-2210) for Samsung Exynos covering multiple high-severity flaws enabling denial of service and information disclosure. Relevant for organizations managing Samsung mobile device fleets; apply available firmware updates.
BSI updated advisories for Samba (WID-SEC-2026-1686, kritisch), GNU libc (WID-SEC-2026-1190, kritisch), Microsoft Windows and Windows Server (WID-SEC-2026-0661), Google Chrome (WID-SEC-2026-2092, WID-SEC-2026-2143), Linux Kernel (multiple advisories), PostgreSQL (WID-SEC-2026-1544), and Red Hat products. These are update-only entries with no new CVEs identified; apply outstanding vendor patches if not yet done.
OPNsense released an update patching a critical root-level vulnerability alongside additional security fixes. Organizations using OPNsense as a perimeter firewall should apply the update immediately.
ACTIVE THREATS AND CAMPAIGNS
NEW — Iran-Linked Threat Actor Deploys Cavern C2 Framework Against Israeli Targets A threat cluster attributed to Iran’s Ministry of Intelligence and Security (MOIS) has been observed using a previously undocumented modular C2 framework called Cavern (also tracked as Cav3rn) in targeted attacks against Israeli IT providers and government organizations. The framework is modular, suggesting capability for tailored post-exploitation activity. Attribution is to a MOIS-affiliated cluster per Check Point Research. While current targeting is focused on Israel, MOIS-linked actors have historically conducted operations against European targets, particularly in the defense, energy, and government sectors. Organizations in those verticals should review network egress for anomalous C2 patterns and ensure threat intelligence feeds are updated with Cavern indicators as they become available.
NEW — Microsoft Teams Vishing Campaign Distributing EtherRAT Threat actors are impersonating corporate IT support staff via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, providing attackers with initial access to corporate networks. This is a social engineering vector that bypasses email security controls entirely. Organizations should brief employees on unsolicited Teams calls requesting software installation, enforce policies requiring IT support requests to originate through ticketing systems, and ensure EDR coverage flags EtherRAT indicators.
NEW — Job Interview Phishing Campaign Targeting Google Accounts A phishing campaign impersonating over 30 major brands — including Adobe, Netflix, Coca-Cola, and OpenAI — is targeting marketing professionals with fake job interview lures designed to harvest Google account credentials. Organizations should alert marketing and HR staff, enforce phishing-resistant MFA on Google Workspace accounts, and review conditional access policies.
ONGOING — PolinRider (North Korean supply chain, malicious packages): audit npm, Packagist, Go, and Chrome extension dependencies. ONGOING — JadePuffer AI-agent ransomware: review detection playbooks for accelerated timelines. ONGOING — Kairos data-theft extortion group: review extortion response posture. ONGOING — ARToken PhaaS targeting Microsoft 365: enforce Conditional Access; audit OAuth grants. ONGOING — Operation DragonReturn (China-nexus DcRAT via fake Indian tax utility): monitor for spear-phishing with tax-themed lures.
SECURITY NEWS AND CONTEXT
A 16-year-old Linux KVM guest-to-host escape (CVE-2026-53359, “Januscape”) has a public PoC causing host kernel panics; a full escape exploit is claimed but not yet released — covered in Critical Vulnerabilities.
A new cross-platform Java-based RAT called QuimaRAT is being offered as malware-as-a-service targeting Windows, Linux, and macOS, priced from $150/month. Organizations should ensure EDR coverage extends to Java-based process execution and cross-platform endpoint visibility.
German Fraunhofer institutes have developed a RISC-V-based secure element chip (OpenTitan-derived) manufactured by Globalfoundries in Dresden, advancing European digital sovereignty in hardware security.
RECOMMENDED ACTIONS
- Patch Adobe ColdFusion CVE-2026-48316 (CVSS 10.0) immediately — actively exploited; isolate servers from the internet if patching cannot be completed within hours and review logs for exploitation indicators.
- Upgrade BeyondTrust Remote Support and Privileged Remote Access to version 25.3.3 or 26.2.1 (CVE-2026-40138, CVE-2026-40139) — restrict management interfaces to trusted networks pending patching.
- Monitor Linux kernel vendor channels for CVE-2026-53359 (Januscape KVM) patches — apply immediately upon release; audit untrusted guest VM workloads in the interim.
- Verify Gitea upgrade to 1.26.3 is complete and audit logs for unauthorized account creation (CVE-2026-20896, now under active probing).
- Upgrade Apache Camel to 4.14.8, 4.18.3, or 4.21.0 to address the BSI-flagged cluster of critical header injection, SSRF, and RCE vulnerabilities.
- Apply OPNsense security update immediately to remediate the critical root-level vulnerability.
- Brief employees on Microsoft Teams vishing attacks distributing EtherRAT; enforce policy requiring IT support requests via ticketing systems only.
- Alert marketing and HR staff to the Google account phishing campaign using fake job interview lures; enforce phishing-resistant MFA on Google Workspace.
- Update threat intelligence feeds and detection rules with Cavern/Cav3rn C2 indicators as they become available; review egress traffic for anomalous C2 patterns in IT and government sector environments.
- Continue remediation of previously reported items: cve-search (CVE-2026-59509), ail-framework (CVE-2026-59510), n8n Execute Command node, Kemp LoadMaster (CVE-2026-8037), SimpleHelp (CVE-2026-48558), Oracle EBS (CVE-2026-46817), IBM Db2 (CVE-2026-10109), BlueHammer.