← All briefings

Flowise · Microsoft Edge · Balbooa Forms / iCagenda

Daily Threat Intelligence Briefing

Date: 2026-07-13 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Today’s most significant new developments are a Metasploit exploit module now available for CVE-2026-41264 (Flowise CSV Agent unauthenticated RCE), materially elevating exploitation risk for that vulnerability. New critical flaws in Flowise (CVE-2026-56271, hardcoded JWT secrets) and Microsoft Edge (CVE-2026-58596, untrusted pointer dereference) were published. The CISA KEV deadline for Balbooa Forms and iCagenda file upload vulnerabilities falls today. RedHook Android malware has gained a novel Wireless ADB persistence mechanism, and the Australian CMS exploitation campaign alert remains active.


Critical Vulnerabilities

CVE-2026-56271 — Flowise (Hardcoded JWT Secrets)

  • Severity: CVSS 9.3
  • EPSS: 0 (newly published; no exploitation data yet)
  • Technical detail: Flowise versions 3.0.13 and earlier use weak hardcoded default JWT secrets (auth_token, refresh_token) with default audience and issuer values (AUDIENCE, ISSUER). Any attacker aware of these defaults can forge valid authentication tokens, bypassing all JWT-based access controls. This is a network-exploitable, unauthenticated authentication bypass affecting all default deployments. Combined with the existing Metasploit module for CVE-2026-41264 (unauthenticated RCE in the same product), a fully weaponized attack chain against Flowise is now publicly available.
  • Exploitation status: No confirmed in-the-wild exploitation; public Metasploit module for co-product CVE-2026-41264 makes Flowise a high-priority target.
  • Remediation: Upgrade to Flowise 3.1.0 or later immediately. Rotate all JWT secrets post-upgrade. Restrict Flowise API exposure to trusted networks only.

CVE-2026-58596 — Microsoft Edge (Chromium-based)

  • Severity: CVSS 8.3
  • EPSS: 0 (newly published)
  • Technical detail: An untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthenticated network attacker to elevate privileges. Affected versions are below 150.0.4078.48. The network-exploitable nature of this privilege escalation — without requiring local access — makes it relevant to enterprise environments where Edge is the standard browser. Note: yesterday’s report covered CVE-2026-58281 (deserialization RCE in Edge, same version threshold); this is a distinct flaw in the same release.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update Microsoft Edge to 150.0.4078.48 or later. Verify deployment via endpoint management. Both CVE-2026-58281 and CVE-2026-58596 are resolved by the same update.

CVE-2026-56291 / CVE-2026-48939 — Balbooa Forms / iCagenda (CISA KEV Deadline: TODAY)

  • Severity: Critical (unrestricted file upload → RCE, unauthenticated)
  • EPSS: Not scored
  • Technical detail: Both vulnerabilities allow unauthenticated arbitrary file upload leading to PHP code execution. CISA KEV remediation deadline is 2026-07-13.
  • Exploitation status: Actively exploited in the wild.
  • Remediation: Patch or disable both extensions immediately. Federal agencies are past deadline; all organizations should treat as urgent.

ONGOING:

  • CVE-2026-41264 (Flowise): STATUS CHANGE — public Metasploit module now available; exploitation risk materially elevated. Upgrade beyond 3.0.13 immediately if not already done.
  • Zimbra Classic Web Client stored XSS (CVE pending): patch urgently; no BSI advisory yet published.
  • CVE-2026-57827 (RSFiles/Joomla, CVSS 10.0): patch or disable; audit web roots for webshells.
  • CVE-2026-15155 (Essential Addons for Elementor): update beyond 6.6.10.
  • CVE-2026-54782 (CoreWCF, CVSS 10.0): upgrade to 1.8.1 or 1.9.1.
  • CVE-2026-52778 (YesWiki, CVSS 9.8, EPSS 0.56): upgrade to 4.6.6.
  • CVE-2026-48282 / CVE-2026-48316 (Adobe ColdFusion): actively exploited; patch or isolate.
  • CVE-2026-55255 (Langflow): actively exploited; patch immediately.
  • CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
  • CVE-2026-46817 (Oracle E-Business Suite): actively exploited; patch immediately.

European Advisories

No new BSI WID or CERT-EU advisories were published in the last 24 hours.

German policy context (Heise Security): The proposed German intelligence law reform that would legally compel the BSI to supply zero-day vulnerabilities to the BND and Verfassungsschutz continues to generate significant commentary. Security leadership in German organizations should monitor legislative progress, as passage would structurally alter the BSI’s defensive mandate. No operational impact at this time.

Lidl data breach (Heise Security): A data protection incident at a third-party service provider resulted in unauthorized access to a file containing Lidl customer personal data. Lidl has notified affected customers. Organizations using the same third-party provider should assess their own exposure. No CVE or technical IOCs published at time of writing.


Active Threats and Campaigns

NEW — RedHook Android Malware: Wireless ADB Persistence A new version of the RedHook Android malware now abuses Android Wireless Debugging (Wireless ADB) to gain shell-level access without requiring a physical USB connection or a paired computer. This represents a meaningful capability upgrade, enabling persistent remote shell access on devices where Wireless ADB is enabled. Organizations with BYOD or managed Android fleets should verify that Wireless ADB is disabled via MDM policy and audit for RedHook indicators.

NEW — Ghostcommit Prompt Injection (Image-Based) Researchers demonstrated that PNG files can carry prompt injection payloads that bypass AI code review tools (CodeRabbit, Bugbot) and manipulate coding agents into exfiltrating repository secrets. This is a STATUS CHANGE from yesterday’s initial disclosure: additional technical detail confirms the technique works against multiple AI review platforms. Implement commit-level secret scanning independent of AI tooling.

ONGOING — Global CMS Exploitation Campaign (ACSC): Active exploitation of vulnerable CMS plugins continues; audit web roots and prioritize Joomla/WordPress patching. ONGOING — jscrambler 8.14.0 npm supply chain compromise: Rotate secrets from any affected build environments; audit CI/CD logs. ONGOING — The Gentlemen ransomware affiliate operation: Review Unit 42 IOCs; update detection rules. ONGOING — Progress ShareFile Storage Zone Controllers: Shutdown directive remains in effect; no CVE published; monitor for updates. ONGOING — WP-SHELLSTORM WordPress mass backdooring: Audit for unauthorized plugins and PHP files. ONGOING — O-UNC-066 vishing / fake Entra passkey enrollment targeting Microsoft 365: Enforce phishing-resistant MFA.


Security News and Context

Flowise Metasploit module: Rapid7 published a weekly update confirming a new exploit module for CVE-2026-41264 (Flowise CSV Agent unauthenticated RCE) and a local privilege escalation module for macOS CVE-2024-27822 (PackageKit ZSH environment, patched in macOS 14.5/13.6.7/12.7.5).

Ryuk ransomware guilty plea: A 34-year-old Armenian national pleaded guilty to deploying Ryuk ransomware against U.S. companies, facing up to 15 years; no new operational IOCs.


  1. Upgrade Flowise to 3.1.0 immediately (CVE-2026-56271): rotate JWT secrets post-upgrade; restrict API to trusted networks. Public Metasploit module for CVE-2026-41264 makes this the highest-priority action today.
  2. Update Microsoft Edge to 150.0.4078.48 to resolve both CVE-2026-58596 (pointer dereference, privilege escalation) and CVE-2026-58281 (deserialization RCE); verify via endpoint management.
  3. Verify Balbooa Forms and iCagenda patches are applied — CISA KEV deadline is today (2026-07-13); treat any unpatched instance as actively compromised.
  4. Disable Wireless ADB on all managed Android devices via MDM policy; audit for RedHook malware indicators.
  5. Enforce commit-level secret scanning independent of AI code review tools to mitigate Ghostcommit-style prompt injection.
  6. Investigate Lidl third-party breach if your organization shares the same service provider; assess data exposure and notify DPO as required under GDPR.
  7. Monitor BSI for Zimbra stored XSS advisory; apply Zimbra patches if not completed from yesterday’s action items.
  8. Update macOS endpoints to 14.5, 13.6.7, or 12.7.5 to address CVE-2024-27822 (PackageKit privilege escalation, now has public Metasploit module).
  9. Continue remediation of previously reported items: CVE-2026-57827 (RSFiles), CVE-2026-15155 (Essential Addons), CVE-2026-54782 (CoreWCF), CVE-2026-52778 (YesWiki), CVE-2026-48282/48316 (ColdFusion), CVE-2026-55255 (Langflow), CVE-2026-8037 (Kemp LoadMaster), CVE-2026-46817 (Oracle EBS).