Week 2026-W29
219 stories tracked this week, up 38 from last week. 6 new KEV entries. 162 ransomware victims claimed.
- vulnerabilities5 sourcesMax severity Adobe ColdFusion flaw now exploited in attacks
A critical Adobe ColdFusion vulnerability (CVE-2026-48282) is being actively exploited in the wild, according to KEVIntel. The flaw carries maximum severity rating and poses an immediate threat to organizations running affected ColdFusion instances.
- vulnerabilities3 sourcesSuspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat group is exploiting patched critical vulnerabilities in Roundcube webmail software at U.S. and Canadian university physics and engineering departments to steal credentials. The campaign leverages flaws including CVE-2024-42009, a critical vulnerability with a CVSS score of 9.3 in the open-source email solution.
- threat intel3 sourcesUAT-7810 continues building ORB networks using new malware
Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.
- vulnerabilitiesCISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.
- vulnerabilitiesiCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity flaws affecting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. Both vulnerabilities received a CVSS score of 10.0, the highest severity rating.
- vulnerabilities6th July – Threat Intelligence Report
A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.
- vulnerabilitiesAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog after the Sysdig Threat Research Team observed active exploitation of a Langflow vulnerability. Langflow is an open-source framework for building AI agents and workflows used by developers, enterprises, and service providers. Attackers are leveraging this flaw for credential harvesting.
- vulnerabilities2 sourcesCritical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical vulnerability in Gitea (CVE-2026-20896) allows attackers to bypass authentication by manipulating a single HTTP header, granting access to repositories and secrets. Researchers have confirmed the flaw is under active exploitation in the wild.
- vulnerabilitiesHitachi Energy e-mesh EMS
Hitachi Energy has disclosed a heap-based buffer overflow vulnerability (CVE-2026-42945) in its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, caused by an NGINX module flaw. The vulnerability, with a CVSS 3.1 score of 8.1, could allow unauthenticated attackers to cause denial of service or execute arbitrary code by sending crafted HTTP requests, particularly on systems without Address Space Layout Randomization (ASLR) enabled. Hitachi Energy recommends applying hotfixes to update NGINX to version 1.30.2 or later, and has provided interim mitigations including configuration changes and operating system upgrades.
- vulnerabilitiesThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have begun probing a critical vulnerability in Gitea Docker images (CVE-2026-20896, CVSS 9.8) just 13 days after its disclosure. The flaw allows unauthenticated users to bypass authentication by spoofing the X-WEBAUTH-USER header, enabling elevated privilege access to the DevOps platform.
- CVE-2026-48282Adobe ColdFusiondue 2026-07-10
- CVE-2026-56290Joomlack Page Builderdue 2026-07-10
- CVE-2026-48908JoomShaper SP Page Builderdue 2026-07-10
- CVE-2026-48939iCagenda iCagendadue 2026-07-13
- CVE-2026-56291Balbooa Formsdue 2026-07-13
- CVE-2026-55255Langflow Langflowdue 2026-07-10
- CVE-2025-3248Langflow LangflowExploitation active since 2026-07-07
- CVE-2026-48282Adobe ColdFusionAdded to CISA KEV 2026-07-07; Added to ENISA EUVD 2026-07-07
- CVE-2026-56290Joomlack Page BuilderAdded to CISA KEV 2026-07-07; Added to ENISA EUVD 2026-07-07
- CVE-2026-48908JoomShaper SP Page BuilderAdded to CISA KEV 2026-07-07; Added to ENISA EUVD 2026-07-06
- CVE-2026-48939iCagenda iCagendaAdded to CISA KEV 2026-07-10; Added to VulnCheck KEV 2026-07-10; Added to ENISA EUVD 2026-07-10
- claimCentury Equitiesclaimed by qilin, unverified
- claimRetelit SpA PIVAclaimed by qilin, unverified
- claimCarolina Agri-Powerclaimed by qilin, unverified
- claimAllied Plumbing & Heatingclaimed by qilin, unverified
- claimEurodeficlaimed by qilin, unverified
- claimSPACElogicclaimed by qilin, unverified
- claimGlobal Strategic Business Process Solutionsclaimed by qilin, unverified
- claimCRZ Construccionesclaimed by qilin, unverified
- claimLopes Lawclaimed by the gentlemen, unverified
- claimCaritaclaimed by the gentlemen, unverified
- claimBDO Greececlaimed by the gentlemen, unverified
- claimDash Door Glassclaimed by the gentlemen, unverified
- claimFerretería Scopazzoclaimed by the gentlemen, unverified
- claimFortrayclaimed by the gentlemen, unverified
- claimMartin Cavaclaimed by the gentlemen, unverified
- claimAveiro Constructors Limitedclaimed by the gentlemen, unverified
- claimWiBeats S.r.l.claimed by deadlock, unverified
- claimLa ville de Ouanganiclaimed by deadlock, unverified
- claimAldaco Avance 2022 S.L.claimed by deadlock, unverified
- claimSchaad, Balass, Menzl and Partner AGclaimed by deadlock, unverified