DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA KEV 2026-07-07 / APSB26-68 // PUBLISHED 2026-07-07

CISA KEV: Adobe ColdFusion Path Traversal RCE (CVE-2026-48282) — Exploited Within Hours of Disclosure

Adobe ColdFusion contains a CVSS 10.0 path traversal vulnerability that leads to arbitrary code execution. CISA added it to the KEV catalog on July 7, 2026 after exploitation was observed within hours of public disclosure, with at least one attempt recorded from an IP geolocated to India. All internet-facing ColdFusion servers should be treated as a fire-drill-category patch priority.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Adobe ColdFusion (all versions prior to July 2026 APSB26-68 patch)
CRITICAL
PUBLIC
PATCHED

Apply Adobe's patches from the July 1, 2026 APSB26-68 advisory immediately. Treat any ColdFusion server accessible from the internet as highest priority regardless of patch lag. FCEB agencies were required to remediate by July 10, 2026 under BOD 26-04.

Monitor IIS/ColdFusion access logs for path traversal sequences (e.g., '../', '%2e%2e%2f') targeting CFIDE or admin endpoints. Alert on unusual child process spawning from the ColdFusion JVM (e.g., cmd.exe, powershell.exe, sh). Correlate with EDR for post-exploitation file writes or reverse-shell beaconing.

EXPORT FORMATTED IOC PACKAGE
Splunk SPL · KQL · Sigma rules · Firewall blocklists — subscriber feature
SUBSCRIBE →
#
TYPE
INDICATOR
CONTEXT
FIRST SEEN
001
IP
103.207.14[.]220
Observed Exploitation Source (India)
2026-07-07
  • https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
  • https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-48282
SHARE BRIEF:✕ Post on Xin Share on LinkedIn