Security Briefing | July 08, 2026 - CISA Adds ColdFusion CVSS 10.0 to KEV With July 10 Deadline, Unpatched GhostLock Flaw Enables Root and Container Escape, China UAT-7810 Deploys LONGLEASH Malware
CISA added four actively exploited vulnerabilities to its KEV catalog including Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow, and two Joomla extensions, with federal agencies required to patch by July 10. Researchers disclosed GhostLock (CVE-2026-43499), a 15-year-old unpatched Linux kernel flaw allowing any logged-in user to gain root and escape containers across all major distributions. Meanwhile, Chinese APT UAT-7810 is expanding its ORB network by deploying new LONGLEASH malware against internet-facing networking devices.
By EACA Summit Content Team

1. CISA KEV Update: Adobe ColdFusion, Langflow, and Joomla Flaws Added With July 10 Patching Deadline
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The most critical is CVE-2026-48282, a path traversal in Adobe ColdFusion (CVSS 10.0) allowing arbitrary code execution, first reported exploited July 07. Also added are the Langflow RCE vulnerability and two Joomla extension flaws. Federal agencies must remediate by July 10, 2026.
Verified Facts
- CISA added CVE-2026-48282 (Adobe ColdFusion, CVSS 10.0) to KEV on July 7, 2026
- CVE-2026-48282 is a path traversal vulnerability leading to arbitrary code execution
- Two Joomla extension flaws and a Langflow vulnerability were also added
- Federal agencies are required to remediate by July 10, 2026
Evidence
- CVE-2026-48282
- CISA KEV catalog entry
- SecurityWeek article: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Impact
Defenders must prioritize patching Adobe ColdFusion, Langflow, and Joomla extensions immediately, as these flaws are under active exploitation and could lead to full system compromise.
Confidence Level: High
Sources The Hacker News | SecurityWeek
2. 15-Year-Old GhostLock Linux Kernel Flaw Enables Root Access and Container Escape
Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability present in all major distributions since 2011. The flaw allows any logged-in user to gain full root control and escape containers without special permissions or network access. No patch is yet available.
Verified Facts
- CVE-2026-43499 (GhostLock) is a Linux kernel flaw present since 2011
- It allows unprivileged local users to gain root privileges and escape containers
- The vulnerability requires no special permissions, unusual settings, or network access
- No patch has been released as of July 8, 2026
Evidence
- CVE-2026-43499
- Nebula Security disclosure
- The Hacker News article
Impact
This flaw poses a critical risk to multi-tenant environments and containerized workloads. Defenders should monitor for patches and implement strict access controls until a fix is available.
Confidence Level: High
Sources The Hacker News | SecurityWeek
3. China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

Cisco Talos reported that Chinese APT group UAT-7810 is actively refining its malware to expand its Operational Relay Box (ORB) network by compromising internet-facing networking devices. The group maintains the LapDogs ORB network, first identified in June 2025, and is deploying new LONGLEASH malware variants.
Verified Facts
- UAT-7810 is a Chinese APT group responsible for the LapDogs ORB network
- The group is using new LONGLEASH malware to compromise networking devices
- Cisco Talos published the findings on July 8, 2026
Evidence
- Cisco Talos report on UAT-7810
- The Hacker News article
Impact
Organizations should monitor for unauthorized access to networking devices, especially those exposed to the internet, and implement strong access controls and monitoring for signs of ORB network activity.
Confidence Level: High
Sources The Hacker News | Cisco Talos
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



