πŸ” Security Pulse Β· 2026-07-14 16:00 UTC

⚑ TL;DR

New critical privilege escalation and remote code execution vulnerabilities disclosed in major enterprise software and open source platforms drive urgent patching needs. Overall threat level elevated to watch.

πŸ” CYBER THREATS

  • πŸ”΄πŸ”΄ Remote Code Execution in ChurchCRM prior to v7.4.0 allows authenticated admin full control over servers, posing critical risk to organizations using this open-source management system [1][2].
  • πŸ”΄ Privilege escalation in OpenShift incluster-checks tool creates privileged pods with host filesystem access, risking container environments and cloud workloads [3].
  • πŸ”΄ Multiple WordPress plugin flaws discovered including WP 2FA (CVE-2026-12988) allowing email impersonation during 2FA setup, and Avada Builder plugin stored XSS vulnerability (CVE-2026-12536) [4][5].
  • πŸ”΄ Critical arbitrary code execution and path traversal vulnerabilities in Adobe ColdFusion versions 2025.9, 2023.20 and earlier threaten enterprise web applications [6][7].
  • πŸ”΄ Bitdefender Total Security’s File Shredder module suffers improper link resolution flaw allowing potential unauthorized file access [8].
  • πŸ”΄ UNIX Symlink vulnerability in openSUSE Tumbleweed’s suricata package enables root escalation by local user [9].
  • πŸ”΄ Use-after-free and integer overflow bugs in Gawk utility could lead to crashes and memory exploits impacting Linux/Unix environments [10].
  • 🟑 Watch: Remote OS command injection in Vitec Flamingo 4.12.2 unauthenticated endpoint could allow attackers remote command execution.
  • 🟑 Watch: Several vulnerabilities in CedarJava policy language might allow authorization bypass or privilege escalations in finely controlled enterprise environments.
  • 🟑 Watch: Firefox for iOS sandbox PDF flaw could allow overwriting files via carefully crafted malicious titles.

πŸ›‘οΈ NATIONAL SECURITY

  • 🟒 Team CISA strengthens collaboration with sports venue security (San Diego Padres) to coordinate cyber-physical safety ahead of critical events, helping reduce risks to large public gatherings.
  • 🟒 CISA South Jersey coalition advances ransomware readiness through workshops with multi-sector partners, enhancing regional cyber resilience against ransomware threats.

⚠️ RISK FLAGS

  • ⚠️⚠️ Immediate patch deployment urged for ChurchCRM and OpenShift users due to active exploitability potential for remote code execution and privilege escalation [1][3].
  • ⚠️ WordPress sites with the identified vulnerable plugins should implement quick updates to mitigate account takeover and XSS attacks [5][4].

🧭 THREAT MOOD

  • 🟑 ELEVATED: Multiple critical vulnerabilities impacting large user bases and infrastructure software escalate urgency for coordinated patching and monitoring but no widespread exploitation yet detected.

πŸ“Ž Sources

  1. CVE-2026-58409 ChurchCRM is an open-source church management s… β€” @CVEnew
  2. CVE-2026-58408 ChurchCRM is an open-source church management s… β€” @CVEnew
  3. CVE-2026-15584 A privilege escalation vulnerability was found … β€” @CVEnew
  4. CVE-2026-12988 The WP 2FA WordPress plugin before 3.1.1.2 doe… β€” @CVEnew
  5. CVE-2026-12536 The Avada (Fusion) Builder plugin for WordPress… β€” @CVEnew
  6. CVE-2026-48364 ColdFusion versions 2025.9, 2023.20 and earlier… β€” @CVEnew
  7. CVE-2026-48363 ColdFusion versions 2025.9, 2023.20 and earlier… β€” @CVEnew
  8. CVE-2026-6851 An Improper link resolution before file access (… β€” @CVEnew
  9. CVE-2026-59674 A UNIX Symbolic Link (Symlink) Following vulner… β€” @CVEnew
  10. CVE-2026-40467 Use After Free vulnerability has been found in … β€” @CVEnew

Educational & informational only β€” not financial advice. Markets carry risk; do your own research.
Serial 20260714-16-v10 Β· 2026-07-14 16:00 UTC Β· pulse.uzylab.com