← All briefings

Adobe ColdFusion · JoomShaper SP Page Builder · Langflow

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-07-08 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

Four new CISA KEV entries dominate today’s briefing: Adobe ColdFusion path traversal (CVE-2026-48282), two Joomla-ecosystem file upload flaws enabling unauthenticated RCE, and a Langflow authorization bypass — all with a remediation deadline of 2026-07-10. BeyondTrust has patched critical pre-authentication flaws in its remote access products. A new Mandiant research publication details a practical technique for recovering ADFS signing keys via Machine DPAPI, enabling Golden SAML attacks. Accenture has confirmed a data breach.

CRITICAL VULNERABILITIES

NEW

CVE-2026-48282 (Adobe ColdFusion)

  • Affected products: Adobe ColdFusion (versions unspecified in advisory; treat all supported versions as affected until vendor clarifies)
  • Severity: Critical (CVSS not yet published)
  • EPSS: Not yet scored
  • Technical detail: A path traversal vulnerability in ColdFusion can lead to arbitrary code execution in the context of the current user. The flaw is distinct from the previously reported CVE-2026-48316 cluster. Path traversal in ColdFusion has historically been chained with file write or deserialization primitives to achieve full RCE. ColdFusion is widely deployed in enterprise and government web application environments across Europe.
  • Exploitation status: Actively exploited — added to CISA KEV on 2026-07-07. CISA BOD 26-04 deadline: 2026-07-10.
  • Remediation: Apply Adobe’s patch immediately. If patching cannot be completed before the deadline, isolate ColdFusion servers from internet-facing exposure. Review logs for path traversal patterns (e.g., ../ sequences in request URIs) and unexpected file writes or process spawning from the ColdFusion service account.

CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Joomlack Page Builder)

  • Affected products: JoomShaper SP Page Builder (Joomla extension); Joomlack Page Builder (Joomla extension)
  • Severity: Critical (CWE-434 unrestricted file upload; CWE-284 improper access control)
  • EPSS: Not yet scored
  • Technical detail: Both vulnerabilities allow unauthenticated attackers to upload arbitrary files to the server, resulting in execution of attacker-supplied PHP code. CVE-2026-48908 is a direct unrestricted upload flaw; CVE-2026-56290 achieves the same outcome via improper access control. Unauthenticated PHP webshell upload is a high-confidence path to full server compromise. Joomla-based sites are common in European public sector, media, and SME environments.
  • Exploitation status: Actively exploited — both added to CISA KEV on 2026-07-07. Deadline: 2026-07-10.
  • Remediation: Update both extensions immediately. If updates are unavailable, disable or remove the affected extensions and audit the web root for recently uploaded PHP files. Review web server access logs for POST requests to upload endpoints from unexpected sources.

CVE-2026-55255 (Langflow)

  • Affected products: Langflow (AI workflow platform, all versions with the affected authorization logic)
  • Severity: Critical (CWE-639 authorization bypass through user-controlled key)
  • EPSS: Not yet scored
  • Technical detail: An authenticated attacker can execute any flow belonging to another user by specifying the victim’s flow ID in the request. The authorization check relies on a user-controlled key rather than server-side ownership validation. In Langflow deployments where flows contain sensitive data, API keys, or execute privileged operations, this enables cross-tenant data access and potential privilege escalation. Langflow is increasingly deployed in enterprise AI automation pipelines.
  • Exploitation status: Actively exploited — added to CISA KEV on 2026-07-07. Deadline: 2026-07-10.
  • Remediation: Apply the vendor patch immediately. Audit Langflow access logs for cross-user flow execution attempts. Review flows for embedded credentials or sensitive data that may have been accessed.

CVE-2026-40138 / CVE-2026-40139 (BeyondTrust Remote Support and Privileged Remote Access)

  • STATUS CHANGE: BSI published advisory WID-SEC-2026-2215 on 2026-07-07, formally flagging these pre-authentication critical flaws (CVSS 9.2) for German and European organizations. No new exploitation confirmed, but BSI classification elevates urgency for European operators.
  • Update: Upgrade to BeyondTrust RS/PRA version 25.3.3 or 26.2.1. Cross-reference WID-SEC-2026-2215.

ONGOING

  • CVE-2026-48316 (Adobe ColdFusion, CVSS 10.0): actively exploited; emergency patch still required if not yet applied.
  • CVE-2026-53359 (Linux KVM “Januscape”): public PoC available; apply kernel patches from distribution vendors as released.
  • CVE-2026-20896 (Gitea Docker): actively probed; verify upgrade to 1.26.3 and audit admin account creation logs.
  • CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
  • CVE-2026-48558 (SimpleHelp): CISA KEV deadline passed; hunt for Djinn Stealer indicators.
  • CVE-2026-46817 (Oracle E-Business Suite): actively exploited; patch immediately.
  • CVE-2026-10109 (IBM Db2): pre-auth RCE; patch and restrict port 50000.
  • BlueHammer (Windows Defender privilege escalation): actively exploited; verify patch applied.

EUROPEAN ADVISORIES

BSI published the following new advisories on 2026-07-07:

WID-SEC-2026-2155 (Adobe ColdFusion, UPDATE, kritisch): covered in Critical Vulnerabilities above.

WID-SEC-2026-2215 (BeyondTrust Privileged Remote Access and Remote Support, NEU, hoch): covered in Critical Vulnerabilities above.

WID-SEC-2026-2225 (Red Hat Enterprise Linux, 389-ds-base, NEU, hoch): CVE-2026-11610, a heap buffer overflow in the SASL I/O layer of 389 Directory Server. An authenticated attacker with a successful SASL bind (SSF > 0) can trigger the overflow to achieve code execution or denial of service. Affects RHEL 7 through 10 and Red Hat Directory Server 11 and 12. Apply Red Hat errata packages listed in the advisory.

WID-SEC-2026-2220 (DriveLock On-Premise and Cloud, NEU, hoch): Multiple vulnerabilities allowing an authenticated remote attacker to disclose information, execute arbitrary code, and escalate privileges. DriveLock is a German endpoint security product with significant European enterprise deployment. Apply vendor-supplied updates immediately.

WID-SEC-2026-2217 (Devolutions Server, NEU, hoch): An authenticated attacker can bypass MFA controls. Devolutions Server is widely used for privileged access management in European SME and mid-market environments. Apply the vendor patch and audit MFA enforcement policies.

WID-SEC-2026-2216 (Synacor Zimbra Classic Web Client, NEU, hoch): Cross-site scripting vulnerability exploitable by an unauthenticated remote attacker. Zimbra is widely deployed in European public sector and enterprise email environments. Apply the Zimbra update; see also Heise Security coverage of this issue.

BSI published multiple Linux Kernel advisory updates (WID-SEC-2025-0453 through WID-SEC-2025-2868, hoch): routine update cycle covering DoS and memory corruption variants. Apply distribution vendor kernel updates as part of standard patching.

BSI updated advisories for HCL BigFix Compliance (Ruby), GnuTLS, and Ruby/Rails (erb gem): apply outstanding vendor patches if not yet done.

ACTIVE THREATS AND CAMPAIGNS

NEW — UAT-7810 LONGLEASH Malware Expanding ORB Network Cisco Talos and Bleeping Computer report that the China-nexus threat actor UAT-7810 continues to develop custom malware, now including a new implant called LONGLEASH, to expand its Operational Relay Box (ORB) network. The actor is primarily targeting unpatched internet-facing networking devices, with Ruckus routers identified as a key vector. ORB networks are used to proxy attack traffic and obscure attribution. European organizations with internet-exposed Ruckus or similar networking devices should prioritize patching and review for indicators of compromise. Talos has published technical details; update detection rules accordingly.

NEW — Vidar Stealer Campaign Using Go Loaders and Code Signing Abuse Unit 42 has published analysis of an active Vidar Stealer campaign combining a loader-as-a-service framework with DLL sideloading via a Go-compiled fake MpClient.dll. The campaign abuses code signing certificates to evade detection and pairs Vidar with an XMRig cryptominer. The fake MpClient.dll sideloading technique is a novel evasion layer. Organizations should ensure EDR rules detect DLL sideloading from non-standard paths and flag unexpected Go-compiled binaries executing in user-writable directories.

NEW — DEBULL Tooling Abusing Microsoft Device-Code Flow Against M365 A campaign observed between late June and early July 2026 is using DEBULL tooling to abuse the Microsoft device-code authentication flow against Microsoft 365 accounts. Lures are collaboration-themed and direct users to the legitimate Microsoft device login page, bypassing fake login page detection. This technique circumvents many phishing-aware user behaviors. Organizations should disable device-code flow in Azure AD Conditional Access policies where not operationally required, and alert users to unsolicited collaboration invitations requesting device login.

NEW — Suspected China-Aligned Actors Exploiting Roundcube Against Universities A suspected China-aligned threat cluster is exploiting patched Roundcube webmail vulnerabilities (including CVE-2024-42009, CVSS 9.3) against physics and engineering departments at North American universities. While current targeting is academic, Roundcube is deployed across European research institutions and public sector organizations. Verify Roundcube is fully patched and review webmail access logs for credential harvesting indicators.

ONGOING — Iran-linked Cavern C2 framework targeting Israeli IT and government: update threat intel feeds with Cavern indicators; review egress for anomalous C2 patterns. ONGOING — Microsoft Teams vishing distributing EtherRAT: brief employees; enforce ticketing-system policy for IT support requests. ONGOING — PolinRider North Korean supply chain malicious packages: audit npm, Packagist, Go, and Chrome extension dependencies. ONGOING — ARToken PhaaS targeting Microsoft 365: enforce Conditional Access; audit OAuth grants.

SECURITY NEWS AND CONTEXT

Mandiant published research on recovering active ADFS token-signing private keys via Machine DPAPI, enabling Golden SAML attacks that bypass MFA and Conditional Access for any SAML-federated application. Organizations using ADFS should audit signing key storage and review privileged access to ADFS servers.

Accenture has confirmed a data breach after a threat actor claimed to have stolen 35 GB of source code and other data. The incident is under investigation; no attribution confirmed.

A hidden authentication backdoor (CVE-2026-11405) has been found in multiple Tenda router firmware versions, allowing unauthenticated administrative access. Organizations should audit their network perimeter for Tenda devices and apply firmware updates or isolate affected devices.

Heise Security reports severe radio-frequency vulnerabilities in Hoymiles inverters affecting hundreds of thousands of photovoltaic installations, potentially allowing remote shutdown or physical destruction by a nearby attacker. Relevant for European critical energy infrastructure operators.

RECOMMENDED ACTIONS

  1. Patch Adobe ColdFusion CVE-2026-48282 immediately — actively exploited, CISA deadline 2026-07-10; isolate from internet if patching is delayed and review logs for path traversal indicators.
  2. Update JoomShaper SP Page Builder (CVE-2026-48908) and Joomlack Page Builder (CVE-2026-56290) immediately — unauthenticated PHP webshell upload, CISA deadline 2026-07-10; audit web root for recently uploaded PHP files.
  3. Patch Langflow (CVE-2026-55255) immediately — authenticated cross-user flow execution, CISA deadline 2026-07-10; audit logs for cross-user access attempts.
  4. Apply BeyondTrust RS/PRA update (CVE-2026-40138/40139) — BSI WID-SEC-2026-2215 now formally flagged; restrict management interfaces to trusted networks.
  5. Apply Red Hat errata for 389-ds-base (CVE-2026-11610) across RHEL 7-10 and Red Hat Directory Server deployments.
  6. Patch DriveLock On-Premise and Cloud (WID-SEC-2026-2220) and Devolutions Server (WID-SEC-2026-2217) — both are European enterprise products with code execution and MFA bypass risks.
  7. Disable Microsoft device-code authentication flow in Azure AD Conditional Access where not required; alert users to DEBULL-style collaboration lures.
  8. Review ADFS deployments for Machine DPAPI key exposure risk per Mandiant research; audit privileged access to ADFS servers.
  9. Audit network perimeter for Tenda devices (CVE-2026-11405 backdoor) and Ruckus devices (UAT-7810 ORB network targeting); apply firmware updates or isolate.
  10. Continue remediation of previously reported items: ColdFusion CVE-2026-48316, Januscape KVM (CVE-2026-53359), Gitea CVE-2026-20896, Kemp LoadMaster (CVE-2026-8037), SimpleHelp (CVE-2026-48558), Oracle EBS (CVE-2026-46817), IBM Db2 (CVE-2026-10109), BlueHammer.