Week of 6 to 12 July 2026
235 qualifying stories tracked from Monday-Sunday calendar week, July 06 to July 12, 2026; change from the prior 7 days: +64 vs prior period; 7 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) entries added from Monday-Sunday calendar week, July 06 to July 12, 2026; 255 leak-site claims observed by tracked feeds from Monday-Sunday calendar week, July 06 to July 12, 2026
Monday to Sunday, UTC. Permalink label: 2026-W28.
- vulnerabilities5 sourcesMax severity Adobe ColdFusion flaw now exploited in attacksSource ↗
A critical Adobe ColdFusion vulnerability (CVE-2026-48282) is being actively exploited in the wild, according to KEVIntel. The flaw carries maximum severity rating and poses an immediate threat to organizations running affected ColdFusion instances.
- vulnerabilities3 sourcesSuspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesSource ↗
A suspected China-aligned threat group is exploiting patched critical vulnerabilities in Roundcube webmail software at U.S. and Canadian university physics and engineering departments to steal credentials. The campaign leverages flaws including CVE-2024-42009, a critical vulnerability with a CVSS score of 9.3 in the open-source email solution.
- threat intel3 sourcesUAT-7810 continues building ORB networks using new malwareSource ↗
Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.
- vulnerabilities3 sourcesCERT/CC Warns of Hidden Admin Backdoor in Tenda Router FirmwareSource ↗
CERT/CC disclosed that multiple versions of Tenda router firmware contain an undocumented authentication backdoor allowing attackers to bypass password verification and gain administrative access to the web management interface. The vulnerability, tracked as CVE-2026-11405, affects Chinese network device manufacturer Tenda's firmware releases.
- vulnerabilities2 sourcesCritical Gitea Flaw Under Active Exploitation, Researchers WarnSource ↗
A critical vulnerability in Gitea (CVE-2026-20896) allows attackers to bypass authentication by manipulating a single HTTP header, granting access to repositories and secrets. Researchers have confirmed the flaw is under active exploitation in the wild.
- vulnerabilities6th July - Threat Intelligence ReportSource ↗
A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.
- vulnerabilitiesCISA Adds Two Known Exploited Vulnerabilities to CatalogSource ↗
CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.
- vulnerabilitiesAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)Source ↗
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog after the Sysdig Threat Research Team observed active exploitation of a Langflow vulnerability. Langflow is an open-source framework for building AI agents and workflows used by developers, enterprises, and service providers. Attackers are leveraging this flaw for credential harvesting.
- vulnerabilitiesHitachi Energy e-mesh EMSSource ↗
Hitachi Energy has disclosed a heap-based buffer overflow vulnerability (CVE-2026-42945) in its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, caused by an NGINX module flaw. The vulnerability, with a CVSS 3.1 score of 8.1, could allow unauthenticated attackers to cause denial of service or execute arbitrary code by sending crafted HTTP requests, particularly on systems without Address Space Layout Randomization (ASLR) enabled. Hitachi Energy recommends applying hotfixes to update NGINX to version 1.30.2 or later, and has provided interim mitigations including configuration changes and operating system upgrades.
- vulnerabilitiesThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After DisclosureSource ↗
Threat actors have begun probing a critical vulnerability in Gitea Docker images (CVE-2026-20896, CVSS 9.8) just 13 days after its disclosure. The flaw allows unauthenticated users to bypass authentication by spoofing the X-WEBAUTH-USER header, enabling elevated privilege access to the DevOps platform.
| Deadlock | 76 claims | +76 vs prior week |
| The Gentlemen | 39 claims | +18 vs prior week |
| Qilin | 31 claims | +8 vs prior week |
| LockBit | 10 claims | +10 vs prior week |
| Safepay | 9 claims | +6 vs prior week |
| Dragonforce | 7 claims | +2 vs prior week |
| Akira | 6 claims | +3 vs prior week |
| Crpx0 | 6 claims | +6 vs prior week |
| Dataleak | 5 claims | +5 vs prior week |
| Chaos | 4 claims | +3 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- CVE-2026-48939iCagenda iCagendadue
- CVE-2026-48908JoomShaper SP Page Builderdue
- CVE-2026-56291Balbooa Formsdue
- CVE-2026-56290Joomlack Page Builderdue
- CVE-2026-48282Adobe ColdFusiondue
- CVE-2026-55255Langflow Langflowdue
- CVE-2008-4128Cisco IOSdue
- CVE-2023-36874Microsoft WindowsEPSS up 11 points in about a week
- CVE-2020-17103Microsoft WindowsAdded to VulnCheck KEV 2026-07-10
- CVE-2026-45586Microsoft WindowsAdded to VulnCheck KEV 2026-07-10
- CVE-2026-48939iCagenda iCagendaAdded to CISA KEV 2026-07-10; Added to VulnCheck KEV 2026-07-10; Added to ENISA EUVD 2026-07-10; Exploitation active since 2026-07-10
- CVE-2026-48908JoomShaper SP Page BuilderAdded to CISA KEV 2026-07-07; Added to ENISA EUVD 2026-07-06; Exploitation active since 2026-07-07
- claimAldaco Avance 2022 S.L.Unverified claim. Claimed by Deadlock.
- claimWiBeats S.r.l.Unverified claim. Claimed by Deadlock.
- claimLa ville de OuanganiUnverified claim. Claimed by Deadlock.
- claimAldaco Avance 2022 S.L.Unverified claim. Claimed by Deadlock.
- claimSchaad, Balass, Menzl and Partner AGUnverified claim. Claimed by Deadlock.
- claimHİDROMEKUnverified claim. Claimed by Deadlock.
- claimKEMEKUnverified claim. Claimed by Deadlock.
- claimKeNHAUnverified claim. Claimed by Deadlock.
- claimLopes LawUnverified claim. Claimed by The Gentlemen.
- claimCaritaUnverified claim. Claimed by The Gentlemen.
- claimBDO GreeceUnverified claim. Claimed by The Gentlemen.
- claimDash Door GlassUnverified claim. Claimed by The Gentlemen.
- claimFerretería ScopazzoUnverified claim. Claimed by The Gentlemen.
- claimFortrayUnverified claim. Claimed by The Gentlemen.
- claimMartin CavaUnverified claim. Claimed by The Gentlemen.
- claimAveiro Constructors LimitedUnverified claim. Claimed by The Gentlemen.
- claimCentury EquitiesUnverified claim. Claimed by Qilin.
- claimRetelit SpA PIVAUnverified claim. Claimed by Qilin.
- claimCarolina Agri-PowerUnverified claim. Claimed by Qilin.
- claimAllied Plumbing & HeatingUnverified claim. Claimed by Qilin.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.