Cyber Threats Daily — 2026-07-10
TITLE: KEV Surge: Today's Federal Deadline Hits ColdFusion, Langflow, and Two Joomla Page Builders
Today's Hot Deadlines (Due 2026-07-10)
Four KEV entries added on 2026-07-07 hit their federal remediation deadline today. Agencies missing patch confirmation should escalate:
- CVE-2026-48282 — Adobe ColdFusion path traversal, added to KEV 2026-07-07 with a same-week remediation window; historically ColdFusion path-traversal chains lead to RCE via CFM upload, so treat any exposed instance as compromised until proven otherwise.
- CVE-2026-55255 — Langflow authorization bypass via user-controlled key; this is the second Langflow KEV entry in under two months (see also CVE-2025-34291), reinforcing that internet-facing LLM orchestration platforms are now a durable exploitation target.
- CVE-2026-48908 (JoomShaper SP Page Builder unrestricted file upload) and CVE-2026-56290 (Joomlack Page Builder improper access control) — paired KEV entries indicate active mass-exploitation campaigns against Joomla content-builder plugins; hunt for webshells under `/images/` and `/tmp/` on affected sites.
Ransomware-Linked KEVs This Cycle
CISA flagged three additions with confirmed ransomware use — prioritize regardless of internal exposure assumptions:
- CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools missing authentication on a critical function; ransomware crews are hitting exposed PeopleSoft portals directly, deadline was 2026-06-15.
- CVE-2026-50751 — Check Point Security Gateway improper authentication, ransomware-linked, deadline 2026-06-11. Perimeter appliance compromise remains the top ransomware entry vector this quarter.
- CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) — both flagged as embedded/supply-chain malicious code with known ransomware use; developer tooling compromise means credential and CI/CD token exposure. Rotate npm tokens and audit build logs from before 2026-05-27.
Supply-Chain and Malicious-Package Cluster
Beyond the two dev-tool entries above, CVE-2026-8398 covers a Daemon Tools Lite installer shipping embedded malicious code — endpoint teams should sweep for the affected build across engineering and QA fleets and treat any host that installed it as untrusted.
Network Edge and Management Plane
The KEV additions show sustained pressure on management-plane appliances — a consistent 2026 theme:
- CVE-2026-0257 — Palo Alto Networks PAN-OS authentication bypass (deadline 2026-06-01); if you haven't already patched, assume management interface compromise and rotate admin credentials plus API keys.
- CVE-2026-20230, CVE-2026-20262, and CVE-2026-20245 — a Cisco triple: Unified Communications Manager SSRF plus two Catalyst SD-WAN Manager flaws (path traversal and output-encoding). Chain risk between the SD-WAN Manager bugs makes this a priority-one Cisco patch cycle.
- CVE-2026-7473 — Arista EOS incomplete comparison bug; deadline 2026-06-23. Low profile but affects ACL evaluation on some platforms.
- CVE-2026-34908 / 34909 / 34910 — three Ubiquiti UniFi OS bugs (access control, path traversal, input validation) added the same day, deadline 2026-06-26; consumer-grade UniFi in SMB and branch offices is the exposure surface.
- CVE-2026-48558 — SimpleHelp authentication bypass, deadline 2026-07-02. SimpleHelp has been recurrently abused for ransomware initial access via MSPs — audit any MSP-managed endpoint tenancy.
- CVE-2026-10520 — Ivanti Sentry OS command injection; Ivanti edge products remain a durable exploitation cluster, deadline 2026-06-14.
Enterprise Server-Side
- CVE-2026-45659 — Microsoft SharePoint Server deserialization of untrusted data; deadline was 2026-07-04. SharePoint deserialization historically yields unauthenticated RCE — if patch state is unknown, hunt for `w3wp.exe` spawning `cmd.exe`/`powershell.exe`.
- CVE-2026-20253 — Splunk Enterprise missing authentication for a critical function; deadline 2026-06-21. Ironic and severe: your SIEM as the entry point.
- CVE-2024-21182 — Oracle WebLogic (unspecified) added to KEV with a 2026-06-04 deadline; the "unspecified" tag plus WebLogic's exploitation history means treat as pre-auth RCE.
- CVE-2026-9082 — Drupal core SQL injection; deadline 2026-05-27. Standard Drupalgeddon-class response required.
- CVE-2026-34926 — Trend Micro Apex One (on-prem) directory traversal; security tooling compromise, deadline 2026-06-04.
Client-Side and Browser
- CVE-2026-11645 — Google Chromium V8 out-of-bounds read/write; deadline 2026-06-23. Standard urgent browser push; verify enterprise Chrome/Edge auto-update health.
- CVE-2025-48595 — Android Framework integer overflow; push through MDM by 2026-06-05 deadline.
Long-Tail and Legacy
CISA added four *very* old CVEs on 2026-05-20 with a 2026-06-03 deadline: CVE-2008-4250 (MS08-067 Windows RPC), CVE-2009-1537 (DirectX), CVE-2009-3459 (Adobe Reader), and CVE-2010-0249 ("Aurora" IE use-after-free). This is a housekeeping sweep — likely driven by continued sightings on unmanaged OT/legacy assets. If any FCEB or regulated environment still runs systems where these apply, they need to be air-gapped or replaced, not patched.
Also noteworthy: CVE-2022-0492 (Linux kernel cgroups v1 privilege escalation) landed in KEV with a 2026-06-05 deadline — container escape implications for older Kubernetes nodes.
Second-Tier and Niche
Quick hits worth patching but not driving IR: CVE-2026-12569 (PTC Windchill/FlexPLM input validation — PLM exposure in manufacturing), CVE-2026-54420 and CVE-2026-48172 (LiteSpeed cPanel Plugin — symlink following and privilege escalation, hosting-provider concern), CVE-2026-28318 (SolarWinds Serv-U DoS), CVE-2026-42271 (BerriAI LiteLLM command injection — another AI-stack entry), CVE-2026-48907 (Widget Factory Joomla Content Editor), CVE-2026-45247 (Mirasvit Full Page Cache Warmer deserialization on Magento), and CVE-2025-67038 (Lantronix EDS5000 device-server code injection — OT/serial-console exposure).
Analyst Takeaways
1. AI infrastructure is now normal KEV inventory. Langflow (twice), LiteLLM, and Nx Console appearances mean LLM orchestration and AI-adjacent dev tooling are part of the standard attack surface — inventory them like any other web app.
2. Joomla plugin ecosystem is under coordinated attack. Two page-builder KEVs on the same day plus the Widget Factory addition suggest a campaign; if you host Joomla, assume scanning is continuous.
3. The 2008–2010 CVE batch is a signal to hunt for unmanaged legacy — not a patching exercise. Ask asset management why these are still in scope.
