Daily briefing · June 30, 2026

Massive Critical Surge: ColdFusion, Storage Concentrator, and Langflow All Hit With CVSS 10 Flaws on June 30

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 30, 2026 delivered one of the heaviest single-day critical vulnerability loads in recent memory, with 43 critical CVEs published and nine entries scoring a perfect CVSS 10.0. No active exploitation (KEV) has been confirmed yet, but the attack surface is exceptionally broad: Adobe ColdFusion, Storage Concentrator appliances, IBM Langflow OSS, and Adobe Campaign Classic are all simultaneously exposed to unauthenticated or near-unauthenticated remote code execution conditions.

Today’s brief
  • Nine CVEs scored a perfect CVSS 10.0 today — all enabling remote code execution with no user interaction required.
  • Adobe ColdFusion received five separate critical flaws covering input validation, path traversal, and unrestricted file upload, all pre-authentication in scope.
  • Storage Concentrator appliances are exposed via an open TCP port 9000 service and an unauthenticated debug script, both allowing root command injection.
  • IBM Langflow OSS carries two critical flaws — one allowing full secret and data exfiltration, another letting authenticated users run arbitrary OS commands — making it a high-value lateral movement target.
43
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56413CVSS 10affects Storage Concentrator
An unauthenticated attacker can send a crafted packet to TCP port 9000 on Storage Concentrator devices and achieve arbitrary command execution — no credentials, no interaction, and the service listens by default, making network-exposed appliances immediately at risk.
2
CVE-2026-56415CVSS 10affects Storage Concentrator
A separate unauthenticated command injection path in Storage Concentrator's debug.pl script allows root-level command execution via a crafted HTTP request, effectively giving any network-reachable attacker full control of the underlying system.
3
CVE-2026-10134CVSS 10affects Langflow OSS
This IBM Langflow OSS flaw allows an attacker to read every secret accessible to the Langflow process, manipulate all flows and stored data, abuse cloud metadata endpoints, and pivot to other tenants — the scope of potential damage extends far beyond the initial foothold.
4
CVE-2026-48281CVSS 10affects ColdFusion
ColdFusion versions through 2025.9 and 2023.20 are vulnerable to improper input validation enabling arbitrary code execution with no user interaction; defenders should treat any internet-facing ColdFusion instance as critically exposed until patched.
5
CVE-2026-48277CVSS 10affects ColdFusion
A second improper input validation flaw in the same ColdFusion versions allows unauthenticated remote code execution with changed scope, compounding the risk for organizations that may not apply all patches from a single advisory simultaneously.
6
CVE-2026-48276CVSS 10affects ColdFusion
Unrestricted file upload in ColdFusion 2025.9 and 2023.20 and earlier enables attackers to upload and execute malicious files without user interaction, a classic and highly reliable path to persistent server compromise.
7
CVE-2026-48282CVSS 10affects ColdFusion
A path traversal vulnerability in ColdFusion can lead to arbitrary code execution, allowing attackers to break out of restricted directory boundaries and potentially access or overwrite sensitive server-side files and executables.
8
CVE-2026-48283CVSS 10affects ColdFusion
Yet another unrestricted file upload flaw in ColdFusion — distinct from CVE-2026-48276 — underscores that this round of Adobe patches addresses multiple independent upload-based code execution vectors that must each be remediated.
9
CVE-2026-48286CVSS 10affects Adobe Campaign Classic (ACC)
Adobe Campaign Classic versions through 7.4.3 build 9396 are affected by an incorrect authorization flaw enabling arbitrary code execution with changed scope and no user interaction, putting marketing automation infrastructure and the sensitive customer data it processes at direct risk.
10
CVE-2026-7873CVSS 9.9affects Langflow OSS
Authenticated Langflow OSS users — including those with low-privilege accounts — can execute arbitrary OS commands and read credential files, meaning a single compromised account is sufficient for complete system takeover and lateral movement across connected infrastructure.
Today’s recommendation: Prioritize emergency patching of all internet-facing ColdFusion instances (applying the full set of today's fixes, not just one), isolate Storage Concentrator appliances from untrusted networks and restrict access to TCP port 9000, and audit Langflow OSS deployments for exposed secrets and unauthorized account access before threat actors begin active scanning.
With nine CVSS 10.0 vulnerabilities published in a single day across widely deployed enterprise products, now is the moment to validate your actual exposure — not just your asset inventory — against these specific attack surfaces.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share