Daily briefing · July 6, 2026

CVSS 10.0 Dual Zero-Days Hit ColdFusion and crawl4ai as Apache Camel Flooded with Critical Flaws

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 6, 2026 brought 191 new vulnerabilities, with 30 reaching critical severity and none yet confirmed under active exploitation. The day is dominated by two perfect-score CVSS 10.0 flaws — one in Adobe ColdFusion enabling unauthenticated remote code execution and another in the crawl4ai LLM crawler allowing container escape via Chromium argument injection. Apache Camel accounts for four additional critical CVEs, signaling a wave of risk across integration middleware deployments.

Today’s brief
  • Two CVSS 10.0 vulnerabilities disclosed: ColdFusion RCE (no user interaction required) and crawl4ai container escape via Chromium argument injection
  • Apache Camel hit with four critical CVEs spanning authentication bypass, deserialization, header injection, and improper access control
  • Coolify self-hosted platform carries two near-perfect flaws including a public PoC, putting self-managed infrastructure at immediate risk
  • Brazil faces intensifying ransomware pressure: three new victims claimed recently by incransom, Doommageddon, and Blackfield across tech, real estate, and manufacturing sectors
30
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-57572CVSS 10affects crawl4ai
A CVSS 10.0 flaw in crawl4ai allows an attacker to inject arbitrary Chromium launch arguments through the Docker API, enabling execution of attacker-controlled commands inside the container — a full container escape with no privilege boundary remaining.
2
CVE-2026-48316CVSS 10affects ColdFusion
Adobe ColdFusion versions 2025.9 and 2023.20 and earlier are vulnerable to unauthenticated remote code execution with scope change, meaning a network-accessible ColdFusion instance can be fully compromised without any user interaction — patch urgently.
3
CVE-2026-34047CVSS 9.9affects coolify
Coolify's terminal WebSocket bootstrap routes lacked authorization middleware, allowing any authenticated user to reach terminal functionality beyond their permitted scope and potentially execute arbitrary commands on managed servers.
4
CVE-2026-34038CVSS 9.9PoCaffects coolify
A public proof-of-concept is already available for this Coolify RCE: users with application write access can inject commands through deployment fields, achieving remote code execution and leaking sensitive environment variables via deployment logs.
5
CVE-2026-48614CVSS 9.9affects Plesk
An improper authorization bug in Plesk's XML API lets an authenticated attacker inject arbitrary configuration directives, write files as root, and achieve full privilege escalation on the underlying server — a complete host takeover from a single API call.
6
CVE-2026-53913CVSS 9.8affects Apache Camel Keycloak
Apache Camel's Keycloak component can be forced into a failing-open state: under specific conditions the KeycloakSecurityPolicy skips role validation entirely, allowing requests that should be rejected to pass through protected routes without a valid token.
7
CVE-2026-46454CVSS 9.8affects Apache Camel
The Apache Camel CometD component forwards all client-supplied Bayeux message headers directly onto the Camel Exchange without filtering, enabling header injection attacks that could manipulate routing logic or expose internal processing headers.
8
CVE-2026-43867CVSS 9.8affects Apache Camel
Apache Camel's PQC component deserializes post-quantum key metadata from AWS Secrets Manager without validation, exposing a classic unsafe deserialization path that could lead to remote code execution if an attacker can influence stored secret values.
9
CVE-2026-48204CVSS 9.8affects Apache Camel
The Apache Camel MongoDB GridFS component allows the GridFS operation to be controlled via an Exchange header by default, enabling any upstream message source to redirect storage operations — a significant improper access control risk in data pipeline deployments.
10
CVE-2026-56140CVSS 9.8affects Apache Camel AWS2 SNS
Apache Camel's AWS2 SNS component applies only an outbound header filter, meaning inbound Camel headers from untrusted sources are not sanitized, creating an input validation gap that could be exploited to manipulate downstream SNS message routing or metadata.
Ransomware today

Three Brazilian organizations were recently claimed as ransomware victims: tecnocurva.com.br (Technology) by incransom, Francisco Imóveis (Consumer Services) by Doommageddon, and redeplastrs.com.br (Manufacturing) by Blackfield. Over the past 30 days, the most active groups targeting Brazil have been lockbit3, ransomhub, lockbit5, thegentlemen, 8base, and arcusmedia, collectively accounting for well over 150 claimed incidents in the country.

tecnocurva.com.br BRincransom · Technology
Francisco Imóveis BRDoommageddon · Consumer Services
redeplastrs.com.br BRBlackfield · Manufacturing
lockbit3 39ransomhub 35lockbit5 26thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actor groups are currently being tracked as active or recently updated: againstthewest, apt73, blackshadow (Iranian-origin), dragonforce, fulcrumsec, and coinbasecartel. While no confirmed victim counts are recorded for these groups at this time, their active monitoring status suggests ongoing reconnaissance or preparation activity that defenders should not dismiss.

Brazil focus

Brazil continues to face sustained ransomware pressure across multiple sectors, with at least eight Brazilian organizations listed as recent victims including Francisco Imóveis, tecnocurva.com.br, redeplastrs.com.br, tambasa.com, Service IT, carvalima.com.br, ezortea.com.br, and flazio.com — the latter attributed to apt73. The breadth of targeted sectors, spanning technology, consumer services, manufacturing, and business services, reflects an indiscriminate targeting posture by groups operating in the region.

Francisco ImóveisDoommageddon · Consumer Services
tecnocurva.com.brincransom · Technology
redeplastrs.com.brBlackfield · Manufacturing
flazio.comapt73 · Technology
tambasa.comincransom
Service ITworldleaks · Business Services
carvalima.com.brincransom · Business Services
ezortea.com.brincransom · Consumer Services
Today’s recommendation: Organizations running ColdFusion, Coolify, Plesk, crawl4ai, or any Apache Camel integration should apply available patches immediately, prioritizing CVE-2026-48316 and CVE-2026-57572 given their maximum severity scores and the existing public PoC for CVE-2026-34038. Review API and middleware exposure at the network perimeter to limit blast radius while patching is underway.
With critical flaws spanning web crawlers, integration middleware, hosting control panels, and enterprise CMS platforms, now is the right moment to validate which of these technologies are reachable in your environment — before an attacker does it for you.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →