
Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV
Post summary
The brief highlights multiple high‑value zero‑days that are actively exploited, with immediate patching advice for Microsoft AD FS, SharePoint, Cisco IOS, and other critical assets.










