π Security Pulse Β· 2026-07-14 16:00 UTC
β‘ TL;DR
New critical privilege escalation and remote code execution vulnerabilities disclosed in major enterprise software and open source platforms drive urgent patching needs. Overall threat level elevated to watch.
π CYBER THREATS
- π΄π΄ Remote Code Execution in ChurchCRM prior to v7.4.0 allows authenticated admin full control over servers, posing critical risk to organizations using this open-source management system [1][2].
- π΄ Privilege escalation in OpenShift incluster-checks tool creates privileged pods with host filesystem access, risking container environments and cloud workloads [3].
- π΄ Multiple WordPress plugin flaws discovered including WP 2FA (CVE-2026-12988) allowing email impersonation during 2FA setup, and Avada Builder plugin stored XSS vulnerability (CVE-2026-12536) [4][5].
- π΄ Critical arbitrary code execution and path traversal vulnerabilities in Adobe ColdFusion versions 2025.9, 2023.20 and earlier threaten enterprise web applications [6][7].
- π΄ Bitdefender Total Securityβs File Shredder module suffers improper link resolution flaw allowing potential unauthorized file access [8].
- π΄ UNIX Symlink vulnerability in openSUSE Tumbleweedβs suricata package enables root escalation by local user [9].
- π΄ Use-after-free and integer overflow bugs in Gawk utility could lead to crashes and memory exploits impacting Linux/Unix environments [10].
- π‘ Watch: Remote OS command injection in Vitec Flamingo 4.12.2 unauthenticated endpoint could allow attackers remote command execution.
- π‘ Watch: Several vulnerabilities in CedarJava policy language might allow authorization bypass or privilege escalations in finely controlled enterprise environments.
- π‘ Watch: Firefox for iOS sandbox PDF flaw could allow overwriting files via carefully crafted malicious titles.
π‘οΈ NATIONAL SECURITY
- π’ Team CISA strengthens collaboration with sports venue security (San Diego Padres) to coordinate cyber-physical safety ahead of critical events, helping reduce risks to large public gatherings.
- π’ CISA South Jersey coalition advances ransomware readiness through workshops with multi-sector partners, enhancing regional cyber resilience against ransomware threats.
β οΈ RISK FLAGS
- β οΈβ οΈ Immediate patch deployment urged for ChurchCRM and OpenShift users due to active exploitability potential for remote code execution and privilege escalation [1][3].
- β οΈ WordPress sites with the identified vulnerable plugins should implement quick updates to mitigate account takeover and XSS attacks [5][4].
π§ THREAT MOOD
- π‘ ELEVATED: Multiple critical vulnerabilities impacting large user bases and infrastructure software escalate urgency for coordinated patching and monitoring but no widespread exploitation yet detected.
π Sources
- CVE-2026-58409 ChurchCRM is an open-source church management sβ¦ β @CVEnew
- CVE-2026-58408 ChurchCRM is an open-source church management sβ¦ β @CVEnew
- CVE-2026-15584 A privilege escalation vulnerability was found β¦ β @CVEnew
- CVE-2026-12988 The WP 2FA WordPress plugin before 3.1.1.2 doeβ¦ β @CVEnew
- CVE-2026-12536 The Avada (Fusion) Builder plugin for WordPressβ¦ β @CVEnew
- CVE-2026-48364 ColdFusion versions 2025.9, 2023.20 and earlierβ¦ β @CVEnew
- CVE-2026-48363 ColdFusion versions 2025.9, 2023.20 and earlierβ¦ β @CVEnew
- CVE-2026-6851 An Improper link resolution before file access (β¦ β @CVEnew
- CVE-2026-59674 A UNIX Symbolic Link (Symlink) Following vulnerβ¦ β @CVEnew
- CVE-2026-40467 Use After Free vulnerability has been found in β¦ β @CVEnew
Educational & informational only β not financial advice. Markets carry risk; do your own research.
Serial 20260714-16-v10 Β· 2026-07-14 16:00 UTC Β· pulse.uzylab.com