Daily briefing · June 30, 2026

Massive Critical Surge: ColdFusion, Storage Concentrator, and Langflow All Hit With CVSS 10 Flaws on June 30

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 30, 2026 delivered one of the heaviest single-day critical vulnerability loads in recent memory, with 43 critical CVEs published and nine entries scoring a perfect CVSS 10.0. No active exploitation (KEV) has been confirmed yet, but the attack surface is exceptionally broad: Adobe ColdFusion, Storage Concentrator appliances, IBM Langflow OSS, and Adobe Campaign Classic are all simultaneously exposed to unauthenticated or near-unauthenticated remote code execution conditions.

Today’s brief
  • Nine CVEs scored a perfect CVSS 10.0 today — all enabling remote code execution with no user interaction required.
  • Adobe ColdFusion received five separate critical flaws covering input validation, path traversal, and unrestricted file upload, all pre-authentication in scope.
  • Storage Concentrator appliances are exposed via an open TCP port 9000 service and an unauthenticated debug script, both allowing root command injection.
  • IBM Langflow OSS carries two critical flaws — one allowing full secret and data exfiltration, another letting authenticated users run arbitrary OS commands — making it a high-value lateral movement target.
43
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56413CVSS 10affects Storage Concentrator
An unauthenticated attacker can send a crafted packet to TCP port 9000 on Storage Concentrator devices and achieve arbitrary command execution — no credentials, no interaction, and the service listens by default, making network-exposed appliances immediately at risk.
2
CVE-2026-56415CVSS 10affects Storage Concentrator
A separate unauthenticated command injection path in Storage Concentrator's debug.pl script allows root-level command execution via a crafted HTTP request, effectively giving any network-reachable attacker full control of the underlying system.
3
CVE-2026-10134CVSS 10affects Langflow OSS
This IBM Langflow OSS flaw allows an attacker to read every secret accessible to the Langflow process, manipulate all flows and stored data, abuse cloud metadata endpoints, and pivot to other tenants — the scope of potential damage extends far beyond the initial foothold.
4
CVE-2026-48281CVSS 10affects ColdFusion
ColdFusion versions through 2025.9 and 2023.20 are vulnerable to improper input validation enabling arbitrary code execution with no user interaction; defenders should treat any internet-facing ColdFusion instance as critically exposed until patched.
5
CVE-2026-48277CVSS 10affects ColdFusion
A second improper input validation flaw in the same ColdFusion versions allows unauthenticated remote code execution with changed scope, compounding the risk for organizations that may not apply all patches from a single advisory simultaneously.
6
CVE-2026-48276CVSS 10affects ColdFusion
Unrestricted file upload in ColdFusion 2025.9 and 2023.20 and earlier enables attackers to upload and execute malicious files without user interaction, a classic and highly reliable path to persistent server compromise.
7
CVE-2026-48282CVSS 10affects ColdFusion
A path traversal vulnerability in ColdFusion can lead to arbitrary code execution, allowing attackers to break out of restricted directory boundaries and potentially access or overwrite sensitive server-side files and executables.
8
CVE-2026-48283CVSS 10affects ColdFusion
Yet another unrestricted file upload flaw in ColdFusion — distinct from CVE-2026-48276 — underscores that this round of Adobe patches addresses multiple independent upload-based code execution vectors that must each be remediated.
9
CVE-2026-48286CVSS 10affects Adobe Campaign Classic (ACC)
Adobe Campaign Classic versions through 7.4.3 build 9396 are affected by an incorrect authorization flaw enabling arbitrary code execution with changed scope and no user interaction, putting marketing automation infrastructure and the sensitive customer data it processes at direct risk.
10
CVE-2026-7873CVSS 9.9affects Langflow OSS
Authenticated Langflow OSS users — including those with low-privilege accounts — can execute arbitrary OS commands and read credential files, meaning a single compromised account is sufficient for complete system takeover and lateral movement across connected infrastructure.
Today’s recommendation: Prioritize emergency patching of all internet-facing ColdFusion instances (applying the full set of today's fixes, not just one), isolate Storage Concentrator appliances from untrusted networks and restrict access to TCP port 9000, and audit Langflow OSS deployments for exposed secrets and unauthorized account access before threat actors begin active scanning.
With nine CVSS 10.0 vulnerabilities published in a single day across widely deployed enterprise products, now is the moment to validate your actual exposure — not just your asset inventory — against these specific attack surfaces.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share