Daily briefing · June 30, 2026
Massive Critical Surge: ColdFusion, Storage Concentrator, and Langflow All Hit With CVSS 10 Flaws on June 30
June 30, 2026 delivered one of the heaviest single-day critical vulnerability loads in recent memory, with 43 critical CVEs published and nine entries scoring a perfect CVSS 10.0. No active exploitation (KEV) has been confirmed yet, but the attack surface is exceptionally broad: Adobe ColdFusion, Storage Concentrator appliances, IBM Langflow OSS, and Adobe Campaign Classic are all simultaneously exposed to unauthenticated or near-unauthenticated remote code execution conditions.
Today’s brief
- Nine CVEs scored a perfect CVSS 10.0 today — all enabling remote code execution with no user interaction required.
- Adobe ColdFusion received five separate critical flaws covering input validation, path traversal, and unrestricted file upload, all pre-authentication in scope.
- Storage Concentrator appliances are exposed via an open TCP port 9000 service and an unauthenticated debug script, both allowing root command injection.
- IBM Langflow OSS carries two critical flaws — one allowing full secret and data exfiltration, another letting authenticated users run arbitrary OS commands — making it a high-value lateral movement target.
43
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
An unauthenticated attacker can send a crafted packet to TCP port 9000 on Storage Concentrator devices and achieve arbitrary command execution — no credentials, no interaction, and the service listens by default, making network-exposed appliances immediately at risk.
2
A separate unauthenticated command injection path in Storage Concentrator's debug.pl script allows root-level command execution via a crafted HTTP request, effectively giving any network-reachable attacker full control of the underlying system.
3
This IBM Langflow OSS flaw allows an attacker to read every secret accessible to the Langflow process, manipulate all flows and stored data, abuse cloud metadata endpoints, and pivot to other tenants — the scope of potential damage extends far beyond the initial foothold.
4
ColdFusion versions through 2025.9 and 2023.20 are vulnerable to improper input validation enabling arbitrary code execution with no user interaction; defenders should treat any internet-facing ColdFusion instance as critically exposed until patched.
5
A second improper input validation flaw in the same ColdFusion versions allows unauthenticated remote code execution with changed scope, compounding the risk for organizations that may not apply all patches from a single advisory simultaneously.
6
Unrestricted file upload in ColdFusion 2025.9 and 2023.20 and earlier enables attackers to upload and execute malicious files without user interaction, a classic and highly reliable path to persistent server compromise.
7
A path traversal vulnerability in ColdFusion can lead to arbitrary code execution, allowing attackers to break out of restricted directory boundaries and potentially access or overwrite sensitive server-side files and executables.
8
Yet another unrestricted file upload flaw in ColdFusion — distinct from CVE-2026-48276 — underscores that this round of Adobe patches addresses multiple independent upload-based code execution vectors that must each be remediated.
9
Adobe Campaign Classic versions through 7.4.3 build 9396 are affected by an incorrect authorization flaw enabling arbitrary code execution with changed scope and no user interaction, putting marketing automation infrastructure and the sensitive customer data it processes at direct risk.
10
Authenticated Langflow OSS users — including those with low-privilege accounts — can execute arbitrary OS commands and read credential files, meaning a single compromised account is sufficient for complete system takeover and lateral movement across connected infrastructure.
Today’s recommendation: Prioritize emergency patching of all internet-facing ColdFusion instances (applying the full set of today's fixes, not just one), isolate Storage Concentrator appliances from untrusted networks and restrict access to TCP port 9000, and audit Langflow OSS deployments for exposed secrets and unauthorized account access before threat actors begin active scanning.
With nine CVSS 10.0 vulnerabilities published in a single day across widely deployed enterprise products, now is the moment to validate your actual exposure — not just your asset inventory — against these specific attack surfaces.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →