ColdFusion CVE-2026-48282 tops the list at CVSS 10
The single most consequential item today is CVE-2026-48282, an Adobe ColdFusion path traversal vulnerability rated Critical with a maximum CVSS of 10. It is listed in the CISA Known Exploited Vulnerabilities catalog, so this is a patch now, not patch eventually. EPSS sits at about 0.29, which is high for a freshly tracked flaw and reflects real exploitation pressure.
If you run internet-facing ColdFusion, treat this as your first action of the day. Path traversal on a public server is the kind of bug that gets turned into full compromise quickly, and the KEV listing confirms attackers are already using it.
The KEV-listed hot movers worth checking
Several other actively exploited CVEs are moving. All of the following carry a KEV listing:
- CVE-2026-55255, a Critical authorization bypass in Langflow through a user-controlled key, CVSS 9.9.
- CVE-2007-3010, a Critical Alcatel OmniPCX Enterprise remote code execution flaw, CVSS 9.8, with EPSS near 0.98.
- CVE-2026-42897, a Microsoft Exchange Server spoofing vulnerability rated High, CVSS 8.8.
- CVE-2026-56290, a Critical Joomlack Page Builder improper access control flaw, CVSS 9.8.
- Two older Windows flaws still in KEV: CVE-2008-4250 (buffer overflow) and CVE-2012-0151 (Authenticode signature verification remote code execution).
One SharePoint flaw not yet in KEV
CVE-2026-55040 is a Critical SharePoint Server security feature bypass, CVSS 9.1. It is not on the KEV list as of today, but the score and product make it a strong candidate to prioritize behind the actively exploited items above. Track its exploitation status rather than assuming it stays quiet.
What the press adds: ServiceNow and WordPress under attack
BleepingComputer reports that a critical ServiceNow code execution flaw, CVE-2026-6875, is now being exploited in attacks. If you run ServiceNow, confirm your instance is patched and review logs for unexpected code execution.
SecurityWeek and Help Net Security both cover the WP2Shell WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, which are being exploited in the wild. Help Net Security frames both as high severity and advises patching immediately. WordPress plugin exploitation tends to be broad and automated, so any delay leaves a window that scanners find fast.
Do this first
Work from confirmed exploitation down to likely next targets:
- Patch ColdFusion for CVE-2026-48282 now. CVSS 10 plus a KEV listing is the top priority.
- Confirm your ServiceNow instance is patched against CVE-2026-6875 and check for signs of code execution.
- Update WordPress and affected plugins for CVE-2026-60137 and CVE-2026-63030.
- Patch Exchange for CVE-2026-42897, and check Langflow, OmniPCX, and Joomlack Page Builder if you run them.
- Verify the older Windows KEV items, CVE-2008-4250 and CVE-2012-0151, are covered on any legacy systems.
Confirm your own patch state
This week's Windows 10 1809 rollups are large: KB5093998 covers 158 CVEs, KB5094128 covers 105, KB5094123 covers 89, and KB5094122 covers 76. Prioritize by exploitation, not raw count.
The free Microsoft Patch Tracker from Siemserva by Senserva ranks your open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily. If you want to check your own tenant, Siemserva also offers a complete audit of Microsoft 365, Intune, Defender, and Entra ID.
Sources
- SecurityWeek: WP2Shell WordPress Vulnerabilities Exploited in the Wild (2026-07-20)
- BleepingComputer: Critical ServiceNow code execution flaw now exploited in attacks (2026-07-20)
- Help Net Security: Two new high severity WordPress vulnerabilities, patch immediately! (2026-07-18)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-21.