VulncastBriefing archive

Daily Brief - 2026-07-14

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-48364

high · CVSS 8.2 · Adobe ColdFusion

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • Uncontrolled Search Path Element
  • Remote Code Execution
  • application server

CVE-2026-58065

high · CVSS 8.1 · Apache Airflow

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.

  • Man-in-the-Middle
  • workflow automation
  • python
  • git
  • ssh

CVE-2026-62185

high · CVSS 7.6 · Argo CD Helm Chart

Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.

  • Security Misconfiguration
  • Remote Code Execution
  • kubernetes
  • containerization

CVE-2026-62242

high · CVSS 8.6 · Spring Boot Admin Server

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.

  • Server-Side Request Forgery
  • java
  • web application

CVE-2026-6875

ServiceNow AI

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

  • Remote Code Execution
  • web application
  • cloud platform