CISA KEV: Adobe ColdFusion, Joomla & Langflow Flaws

🔴 Critical | Source: The Hacker News CISA has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue, affecting Adobe ColdFusion, Joomla, and Langflow. One flaw in Adobe ColdFusion carries a maximum CVSS score of 10.0 and enables arbitrary code execution via path traversal. Active exploitation means threat actors are already leveraging these weaknesses against real targets, making prompt patching urgent. Security Architect’s Take: Audit your environment immediately for exposed instances of Adobe ColdFusion, Joomla CMS, and Langflow — particularly any internet-facing deployments hosted on cloud infrastructure — and apply available patches or mitigations before CISA’s KEV remediation deadline. If patching cannot be completed immediately, consider placing these services behind a WAF or restricting network access as a temporary control. ...

8 July 2026 · ZX Cloud Security

CVE-2026-14904: AWS RES Symlink File Read Flaw

🔴 Critical | Source: AWS Security Bulletins A path traversal vulnerability (CVE-2026-14904) in AWS Research and Engineering Studio (RES) allows any authenticated user to read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key with a symbolic link. Because the cluster-manager process runs as root, attackers can access highly sensitive files including other users’ SSH private keys and application secrets. All RES versions up to and including 2026.03 are affected. ...

7 July 2026 · ZX Cloud Security

Writer AI Session Token Leak: Cross-Tenant Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability in Writer, an enterprise AI platform, allowed attackers to leak session tokens across different customer tenants simply by tricking a user into clicking a malicious link. Dubbed ‘WriteOut’ by Sand Security Research, the flaw meant a complete outsider could gain full access to any Writer tenant without prior credentials. The vulnerability has since been patched by Writer. Security Architect’s Take: If your organisation uses Writer, confirm with your vendor that the patch has been applied to your tenant and review recent session and access logs for any anomalous cross-tenant activity. More broadly, this is a prompt reminder to assess any enterprise AI platforms in your stack for session isolation controls and enforce short-lived, scoped session tokens wherever possible. ...

7 July 2026 · ZX Cloud Security

CVE-2026-10536: Azure HTTP/2 UAF Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-10536 is a Use-After-Free (UAF) vulnerability in the HTTP/2 stream-dependency tree handling, affecting Azure services. UAF flaws occur when a programme continues to use memory after it has been freed, which can allow an attacker to execute arbitrary code or cause a service crash. This vulnerability is particularly concerning given how broadly HTTP/2 is used across cloud-native workloads and APIs. Security Architect’s Take: Review any Azure services and self-managed workloads that expose HTTP/2 endpoints, and apply Microsoft’s patches immediately — UAF vulnerabilities with network-reachable attack surfaces can be exploited remotely and should be treated as urgent. Consider temporarily enforcing HTTP/1.1 on critical API gateways or load balancers as a short-term mitigation if patching cannot be completed immediately. ...

7 July 2026 · ZX Cloud Security

Tenda Router Backdoor CVE-2026-11405: CERT/CC Warning

🔴 Critical | Source: The Hacker News Multiple Tenda router firmware versions contain a hidden backdoor (CVE-2026-11405) that allows an attacker to bypass password authentication and gain full administrative access to the device’s web management interface. The backdoor is undocumented, meaning it was not disclosed by the manufacturer, raising concerns about intentional insertion. This poses a significant risk to any network where Tenda devices are deployed, particularly in environments where router management interfaces are internet-facing. ...

7 July 2026 · ZX Cloud Security

BeyondTrust Auth Bypass CVE-2026-40138 Patched

🔴 Critical | Source: The Hacker News BeyondTrust has patched two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access (PRA) products, including CVE-2026-40138 which carries a CVSS score of 9.2. The flaws can be exploited by unauthenticated attackers, potentially granting full control of affected systems. Given that these products are widely used to manage privileged access to enterprise and cloud infrastructure, the blast radius of a successful exploit is significant. ...

7 July 2026 · ZX Cloud Security

CVE-2026-48282: Adobe ColdFusion Path Traversal RCE

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A path traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) allows attackers to navigate outside restricted directories and execute arbitrary code under the permissions of the currently running user. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ColdFusion is commonly used to serve web applications, meaning a successful attack could lead to full server compromise. Security Architect’s Take: Prioritise patching any internet-facing or internally accessible ColdFusion instances immediately ahead of the 10 July 2026 CISA remediation deadline, and consider placing them behind a web application firewall with path traversal detection rules as an interim compensating control whilst patches are applied. ...

7 July 2026 · ZX Cloud Security

CVE-2026-48908: JoomShaper SP Page Builder RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the JoomShaper SP Page Builder plugin for Joomla allows unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, which can then be executed on the server. This effectively grants full remote code execution to anyone with network access to the site, requiring no credentials whatsoever. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ...

7 July 2026 · ZX Cloud Security

CVE-2026-55255: Langflow Auth Bypass Exploited

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A vulnerability in Langflow, an open-source tool for building AI-powered workflows, allows an authenticated attacker to execute any other user’s workflow simply by knowing or guessing its ID. This is an authorisation bypass flaw, meaning the application fails to verify that a user actually owns the flow they are requesting to run. Because Langflow is actively exploited in the wild and listed on the CISA KEV catalogue, this is a serious and immediate risk for any organisation running the platform. ...

7 July 2026 · ZX Cloud Security

CVE-2026-56290: Joomlack Page Builder RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the Joomlack Page Builder plugin allows unauthenticated attackers to upload arbitrary files to a server, which can be exploited to execute malicious code remotely. This is classified as an improper access control flaw, meaning no login or privileges are required to exploit it. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ...

7 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options