Daily briefing · July 6, 2026
CVSS 10.0 Dual Zero-Days Hit ColdFusion and crawl4ai as Apache Camel Flooded with Critical Flaws
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
July 6, 2026 brought 191 new vulnerabilities, with 30 reaching critical severity and none yet confirmed under active exploitation. The day is dominated by two perfect-score CVSS 10.0 flaws — one in Adobe ColdFusion enabling unauthenticated remote code execution and another in the crawl4ai LLM crawler allowing container escape via Chromium argument injection. Apache Camel accounts for four additional critical CVEs, signaling a wave of risk across integration middleware deployments.
Today’s brief
- Two CVSS 10.0 vulnerabilities disclosed: ColdFusion RCE (no user interaction required) and crawl4ai container escape via Chromium argument injection
- Apache Camel hit with four critical CVEs spanning authentication bypass, deserialization, header injection, and improper access control
- Coolify self-hosted platform carries two near-perfect flaws including a public PoC, putting self-managed infrastructure at immediate risk
- Brazil faces intensifying ransomware pressure: three new victims claimed recently by incransom, Doommageddon, and Blackfield across tech, real estate, and manufacturing sectors
Critical highlights
1
A CVSS 10.0 flaw in crawl4ai allows an attacker to inject arbitrary Chromium launch arguments through the Docker API, enabling execution of attacker-controlled commands inside the container — a full container escape with no privilege boundary remaining.
2
Adobe ColdFusion versions 2025.9 and 2023.20 and earlier are vulnerable to unauthenticated remote code execution with scope change, meaning a network-accessible ColdFusion instance can be fully compromised without any user interaction — patch urgently.
3
Coolify's terminal WebSocket bootstrap routes lacked authorization middleware, allowing any authenticated user to reach terminal functionality beyond their permitted scope and potentially execute arbitrary commands on managed servers.
4
A public proof-of-concept is already available for this Coolify RCE: users with application write access can inject commands through deployment fields, achieving remote code execution and leaking sensitive environment variables via deployment logs.
5
An improper authorization bug in Plesk's XML API lets an authenticated attacker inject arbitrary configuration directives, write files as root, and achieve full privilege escalation on the underlying server — a complete host takeover from a single API call.
6
Apache Camel's Keycloak component can be forced into a failing-open state: under specific conditions the KeycloakSecurityPolicy skips role validation entirely, allowing requests that should be rejected to pass through protected routes without a valid token.
7
The Apache Camel CometD component forwards all client-supplied Bayeux message headers directly onto the Camel Exchange without filtering, enabling header injection attacks that could manipulate routing logic or expose internal processing headers.
8
Apache Camel's PQC component deserializes post-quantum key metadata from AWS Secrets Manager without validation, exposing a classic unsafe deserialization path that could lead to remote code execution if an attacker can influence stored secret values.
9
The Apache Camel MongoDB GridFS component allows the GridFS operation to be controlled via an Exchange header by default, enabling any upstream message source to redirect storage operations — a significant improper access control risk in data pipeline deployments.
10
Apache Camel's AWS2 SNS component applies only an outbound header filter, meaning inbound Camel headers from untrusted sources are not sanitized, creating an input validation gap that could be exploited to manipulate downstream SNS message routing or metadata.
Ransomware today
Three Brazilian organizations were recently claimed as ransomware victims: tecnocurva.com.br (Technology) by incransom, Francisco Imóveis (Consumer Services) by Doommageddon, and redeplastrs.com.br (Manufacturing) by Blackfield. Over the past 30 days, the most active groups targeting Brazil have been lockbit3, ransomhub, lockbit5, thegentlemen, 8base, and arcusmedia, collectively accounting for well over 150 claimed incidents in the country.
tecnocurva.com.br BRincransom · Technology
Francisco Imóveis BRDoommageddon · Consumer Services
redeplastrs.com.br BRBlackfield · Manufacturing
lockbit3 39ransomhub 35lockbit5 26thegentlemen 208base 20arcusmedia 19
Active groups & APTs
Several threat actor groups are currently being tracked as active or recently updated: againstthewest, apt73, blackshadow (Iranian-origin), dragonforce, fulcrumsec, and coinbasecartel. While no confirmed victim counts are recorded for these groups at this time, their active monitoring status suggests ongoing reconnaissance or preparation activity that defenders should not dismiss.
Brazil focus
Brazil continues to face sustained ransomware pressure across multiple sectors, with at least eight Brazilian organizations listed as recent victims including Francisco Imóveis, tecnocurva.com.br, redeplastrs.com.br, tambasa.com, Service IT, carvalima.com.br, ezortea.com.br, and flazio.com — the latter attributed to apt73. The breadth of targeted sectors, spanning technology, consumer services, manufacturing, and business services, reflects an indiscriminate targeting posture by groups operating in the region.
Francisco ImóveisDoommageddon · Consumer Services
tecnocurva.com.brincransom · Technology
redeplastrs.com.brBlackfield · Manufacturing
flazio.comapt73 · Technology
tambasa.comincransom
Service ITworldleaks · Business Services
carvalima.com.brincransom · Business Services
ezortea.com.brincransom · Consumer Services
Today’s recommendation: Organizations running ColdFusion, Coolify, Plesk, crawl4ai, or any Apache Camel integration should apply available patches immediately, prioritizing CVE-2026-48316 and CVE-2026-57572 given their maximum severity scores and the existing public PoC for CVE-2026-34038. Review API and middleware exposure at the network perimeter to limit blast radius while patching is underway.
With critical flaws spanning web crawlers, integration middleware, hosting control panels, and enterprise CMS platforms, now is the right moment to validate which of these technologies are reachable in your environment — before an attacker does it for you.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →