Cyber Risk Brief: 13 July 2026
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
This week's register is dominated by a BOD 26-04 KEV pile-up and a credential pipeline into ransomware. Four actively exploited or KEV-listed application flaws lead it: Adobe ColdFusion path-traversal RCE (T1), Ivanti Sentry unauthenticated root command injection carried forward from June (T2), a second Langflow KEV — IDOR enabling cross-tenant flow execution (T3), distinct from last week's JadePuffer chain — and dual Joomla page-builder RCE flaws already producing webshells (T4). FortiBleed (T5) converts FortiGate VPN/auth sniffing into INC and Lynx ransomware leverage with no CVE patch to apply. BeyondTrust RS/PRA flaws (T6) and Januscape KVM guest-to-host (T7) close the privileged-access and hypervisor lanes before weaponization. Mount Royal University (T8) confirms Alberta FOIP-facing ransomware damage; the City of Winkler, Manitoba closed offices after a cybersecurity incident on 8–9 July — Canadian public-sector pressure in the same window as federal KEV deadlines.
Threat Register: 13/07/2026
| Threat | |||||
|---|---|---|---|---|---|
| T1 | Adobe ColdFusion Path Traversal RCE via RDS FILEIO (CVE-2026-48282) CISA added Adobe ColdFusion CVE-2026-48282 to KEV on 7 July 2026 with a BOD 26-04 remediation deadline of 10 July 2026. The flaw is a path traversal in RDS FILEIO that enables arbitrary file write and remote code execution when RDS is enabled and authentication is disabled — RDS is not enabled by default. NVD CVSS 3.1 base is 10.0; EPSS is 0.28583. Exploitation was observed after watchTowr analysis and honeypot telemetry (Help Net Security). Adobe APSB26-68 ships ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. | 10.0 | 28.58% | Critical | Immediate |
| T2 | Ivanti Sentry Unauthenticated OS Command Injection (CVE-2026-10520) + Admin Creation (CVE-2026-10523) CVE-2026-10520 is an unauthenticated OS command injection in Ivanti Sentry scored CVSS 10.0 with EPSS 0.99041; CISA added it to KEV on 11 June 2026. Companion CVE-2026-10523 (CVSS 9.9, EPSS 0.47190) enables unauthenticated administrator account creation and is not KEV-listed. watchTowr published a PoC; Shadowserver observed exploitation and backdoors. Ivanti stated the KEV listing was based on honeypot attempts. Patches: R10.5.2 / R10.6.2 / R10.7.1. Remains an active edge-appliance risk in the 7–12 July window. | 10.0 | 99.04% | Critical | Immediate |
| T3 | Langflow IDOR — Cross-Tenant Flow Execution & Credential Harvest (CVE-2026-55255) CISA added Langflow CVE-2026-55255 to KEV on 7 July 2026 with a BOD 26-04 deadline of 10 July 2026. The flaw is an IDOR on /api/v1/responses that accepts a victim flow UUID, enabling cross-tenant flow execution and credential harvest. NVD CVSS 3.1 base is 8.4 (SecurityWeek has cited 9.9; this register uses NVD). EPSS is 0.00467. Sysdig observed exploitation from about 26 June chaining with CVE-2026-33017. Patch: Langflow 1.9.1. Distinct from JadePuffer CVE-2025-3248 / CVE-2026-33017 covered in the prior brief. | 8.4 | < 1% | Critical | Immediate |
| T4 | Joomla Extensions KEV Batch — SP Page Builder & Page Builder CK (CVE-2026-48908 / CVE-2026-56290) CISA listed two Joomla page-builder extension flaws on KEV under BOD 26-04 with a 10 July 2026 federal deadline. CVE-2026-48908 in SP Page Builder (CVSS 10.0, EPSS 0.01569) is improper access control enabling unauthenticated RCE via custom icon upload; fixed in 6.6.2; observed outcomes include hidden admin accounts and a PHP file-manager backdoor. CVE-2026-56290 in Page Builder CK (CVSS 10.0, EPSS 0.02912) is unauthenticated arbitrary file upload to RCE; fixed in 3.6.0 on 27 June; webshells appeared within hours of exploitation reporting. | 10.0 | 1.57% | Critical | Immediate |
| T5 | FortiBleed Credential Theft Campaign Linked to INC / Lynx Ransomware SOCRadar (via BleepingComputer and SecurityWeek) links the FortiBleed campaign to INC and Lynx ransomware negotiation panels. Roughly 430,000 FortiGate devices were targeted; about 19,000 sniffers were identified; around 110 million credentials were harvested; about 11,000 devices remained compromised after notification; roughly 500 servers and about 20 operators supported the campaign. FortiGate sniffers intercept VPN and authentication traffic. A backdoor username adminin was reported. Researchers believe a possible Nextcloud zero-day was used for expansion; details have not been released. No CVE applies; no vendor patch closes the campaign. | — | — | Critical | Post-incident |
| T6 | BeyondTrust Remote Support / PRA Critical Flaws (CVE-2026-40138 / CVE-2026-40139) BeyondTrust disclosed CVE-2026-40138 and CVE-2026-40139 in Remote Support and Privileged Remote Access, both scored 9.2 under CVSS 4.0 (CVSS 3.1: 8.1 and 9.8). EPSS values are 0.00417 and 0.00653. Cloud tenants were patched on 21 April 2026; self-hosted deployments through version 25.3.2 require 25.3.3 or later. Exploitation requires a specific authentication configuration to be enabled. BleepingComputer reports no confirmed in-wild exploitation. Not on CISA KEV. | 9.2 | < 1% | High | 7 days |
| T7 | Januscape — Linux KVM Guest-to-Host Shadow MMU UAF (CVE-2026-53359) Januscape (CVE-2026-53359) is a use-after-free in the Linux KVM/x86 shadow MMU present for roughly 16 years, disclosed via Google's kvmCTF. Guest root can reach the host on Intel and AMD. NVD has not published a CVSS score; EPSS is 0.00176. A public PoC triggers host panic; a full escape exploit is not released. On some distributions where /dev/kvm is world-writable, a local unprivileged user can cause root-level crash impact. Patch: kernel commit 81ccda30b4e8; companion CVE-2026-46113. Not on CISA KEV. | — | < 1% | High | 7 days |
| T8 | Mount Royal University Ransomware — H-Drive Exfiltration (CMD Organization) Mount Royal University confirmed a ransomware incident around 17 June 2026, with July confirmation that H-drive contents were exfiltrated and deleted and that the J-drive was wiped without evidence of copying. CMD Organization claimed responsibility and demanded approximately 30 BTC (~$1.9M); leaked samples include passport scans. The university reported the matter to Alberta's Information and Privacy Commissioner. Alberta FOIP applies; this is not a PIPEDA federal-institution framing. No CVE applies. | — | — | High | Post-incident |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Strategic context
BOD 26-04 KEV pile-up, credential ransomware pipelines, and a second Langflow surface
- CISA packed ColdFusion CVE-2026-48282 (T1), Langflow CVE-2026-55255 (T3), and two Joomla page-builder flaws (T4) onto KEV under BOD 26-04 with a shared 10 July federal deadline — a single-week pile-up of internet-facing application RCE and AI-orchestration exposure. Organizations still clearing last week's SharePoint and SimpleHelp KEV clocks now inherit a second federal due date on ColdFusion, Langflow, and Joomla extensions.
- FortiBleed (T5) shows the ransomware economy's other half: not a new FortiGate CVE to patch, but mass VPN/auth credential theft feeding INC and Lynx negotiation panels — roughly 110 million credentials and thousands of devices still compromised after notification. Edge appliances without MFA and forced rotation remain the ransomware initial-access path even when the vendor has no CVE to ship.
- Canadian public-sector pressure is concrete this week. Mount Royal University (T8) confirmed H-drive exfiltration under Alberta FOIP with a CMD Organization ransom claim, while the City of Winkler, Manitoba closed offices after a cybersecurity incident on 8–9 July. For boards, the dual signal is that education and municipal operators are in the same ransomware market as enterprises — and provincial privacy obligations attach whether or not a federal KEV listing exists.
Threat Actor Profiling
T5 is attributed to INC Ransom / Lynx operators via SOCRadar's FortiBleed infrastructure analysis. T8 is claimed by CMD Organization. T1–T4 exploitation is unattributed beyond CISA KEV / Sysdig / SecurityWeek campaign reporting. T6 has no confirmed in-wild adversary. T7 is researcher disclosure with a public host-panic PoC. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed threat actor (ColdFusion exploitation) | Enterprise application, Web application hosting | T1190T1059T1505.003 | RDS-enabled ColdFusion with authentication disabled → CVE-2026-48282 path traversal / arbitrary file write → RCE → persistence on application host. |
| T2 | Unattributed threat actor (Ivanti Sentry exploitation / honeypot + Shadowserver) | Enterprise edge, Mobile / remote access | T1190T1059.004T1136T1505 | Unauthenticated OS command injection on Ivanti Sentry (CVE-2026-10520) and/or unauthenticated admin creation (CVE-2026-10523) → root or admin foothold → backdoor persistence observed by Shadowserver. |
| T3 | Unattributed threat actor (Sysdig-observed Langflow IDOR campaign) | AI/ML infrastructure, Cross-sector enterprise | T1190T1078T1552T1528 | IDOR against Langflow /api/v1/responses with victim flow UUID (CVE-2026-55255) → cross-tenant flow execution → credential harvest; observed chaining with CVE-2026-33017 from ~26 June (Sysdig). |
| T4 | Unattributed threat actor (Joomla extension webshell campaigns) | Web / CMS, Marketing and public sites | T1190T1505.003T1136 | Unauthenticated upload / access-control bypass on SP Page Builder or Page Builder CK → RCE → webshells, hidden admin accounts, PHP file-manager backdoors. |
| T5 | INC Ransom / Lynx operators (SOCRadar attribution to shared FortiBleed infrastructure) | Cross-sector enterprise, VPN / edge | T1040T1557T1078T1486 | FortiGate sniffer deployment (FortiBleed) → VPN/auth credential interception (~110M credentials reported) → access via stolen credentials → INC / Lynx ransomware negotiation leverage; backdoor username adminin reported. |
| T6 | No confirmed adversary (BeyondTrust advisory — patch before weaponization) | Privileged access / remote support | T1190T1078T1021 | n/a — no confirmed exploitation reported; hypothetical path is abuse of CVE-2026-40138 / CVE-2026-40139 on RS/PRA with required auth configuration enabled → privileged remote session control. |
| T7 | Unattributed / researcher disclosure (Januscape — PoC only) | Cloud IaaS, Private virtualization | T1068T1611T1499 | Guest root (or local unprivileged where /dev/kvm is world-writable) → CVE-2026-53359 shadow MMU UAF → host panic (public PoC) or potential host escape (full exploit not released). |
| T8 | CMD Organization (claimed) | Higher education, Canadian public sector | T1486T1048T1485 | Initial access (vector not publicly confirmed) → H-drive exfiltration and deletion; J-drive wipe → ~30 BTC / ~$1.9M ransom claim with passport-scan samples → Alberta privacy commissioner notification. |
▶Table methodology & sourcing notes
- Actors are named only where a source attributes the incident; otherwise “unattributed.” T5 maps INC/Lynx from SOCRadar's FortiBleed panel and victim-overlap analysis; T8 maps CMD Organization from the group's claim and BleepingComputer/SecurityWeek reporting — additional techniques beyond published reporting would be inference.
- All CVSS, EPSS, and KEV values were verified directly against NVD, the FIRST EPSS API, and the CISA KEV catalog (2026-07-13); they are not carried from secondary reporting. Januscape (T7) has no NVD base score yet — cvss is null.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Adobe ColdFusion Path Traversal RCE via RDS FILEIO (CVE-2026-48282) |
| A.8.8, A.8.9, A.8.20, A.8.25, A.8.16 | ID.AM-01, ID.RA-01, PR.PS-01, PR.PS-02, DE.CM-01 | CIS 7, CIS 12, CIS 13, CIS 16 | — | SI-2, RA-5, SC-7, CM-7 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T2Ivanti Sentry Unauthenticated OS Command Injection (CVE-2026-10520) + Admin Creation (CVE-2026-10523) |
| A.8.8, A.8.9, A.8.20, A.5.15, A.8.16 | ID.AM-01, PR.PS-01, PR.AA-01, DE.CM-01, RS.MI-01 | CIS 1, CIS 7, CIS 12, CIS 5 | — | SI-2, RA-5, SC-7, AC-17 | B-13 Patch Mgmt, B-13 Vulnerability Management, B-13 Access Control | — |
T3Langflow IDOR — Cross-Tenant Flow Execution & Credential Harvest (CVE-2026-55255) |
| A.8.8, A.8.25, A.8.16, A.8.31, A.5.19 | ID.AM-02, ID.RA-01, PR.PS-06, DE.CM-09, GV.SC-05 | CIS 2, CIS 7, CIS 16, CIS 13 | — | SI-2, RA-5, CM-7, SA-12 | B-13 Third-Party Risk, B-13 Patch Mgmt, B-13 Governance | A.4.4, A.6.2.6, A.10.3 |
T4Joomla Extensions KEV Batch — SP Page Builder & Page Builder CK (CVE-2026-48908 / CVE-2026-56290) |
| A.8.8, A.8.9, A.8.25, A.8.16, A.5.19 | ID.AM-02, PR.PS-01, DE.CM-01, DE.CM-09, RS.MI-01 | CIS 2, CIS 7, CIS 16, CIS 13 | — | SI-2, RA-5, CM-7, SI-3 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T5FortiBleed Credential Theft Campaign Linked to INC / Lynx Ransomware |
| A.5.17, A.8.5, A.8.16, A.5.25, A.8.20 | PR.AA-01, PR.AA-05, DE.CM-01, RS.MI-01, ID.RA-01 | CIS 5, CIS 6, CIS 8, CIS 17 | — | IA-2, IA-5, SI-4, AC-17 | B-13 Access Control, B-13 Vulnerability Management, B-13 Governance | — |
T6BeyondTrust Remote Support / PRA Critical Flaws (CVE-2026-40138 / CVE-2026-40139) |
| A.8.8, A.5.15, A.5.17, A.8.5, A.8.2 | ID.AM-02, PR.AA-01, PR.AA-05, PR.PS-02, ID.RA-01 | CIS 2, CIS 5, CIS 6, CIS 7 | — | SI-2, AC-17, IA-2, CM-7 | B-13 Patch Mgmt, B-13 Access Control | — |
T7Januscape — Linux KVM Guest-to-Host Shadow MMU UAF (CVE-2026-53359) |
| A.8.8, A.8.9, A.8.31, A.8.16, A.5.23 | ID.AM-01, PR.PS-01, PR.PS-02, DE.CM-09, ID.RA-01 | CIS 1, CIS 7, CIS 16, CIS 5 | — | SI-2, CM-7, SC-7, RA-5 | B-13 Patch Mgmt, B-13 Vulnerability Management, B-13 Governance | — |
T8Mount Royal University Ransomware — H-Drive Exfiltration (CMD Organization) |
| A.5.24, A.5.29, A.8.13, A.8.14, A.5.34 | RS.CO-02, PR.DS-01, PR.DS-11, ID.RA-01, GV.OC-03 | CIS 3, CIS 11, CIS 17, CIS 6 | — | CP-9, CP-10, IR-4, IR-6 | B-13 Governance, B-13 Access Control, B-13 Third-Party Risk | — |
Privacy Act / PIPEDA & OSFI: T8 (Mount Royal) is Alberta FOIP jurisdiction — do not map PIPEDA. T1–T4 carry CISA KEV / BOD 26-04 federal deadlines (ColdFusion, Langflow, Joomla; Ivanti Sentry KEV carry-forward). T5 FortiBleed is a no-CVE credential campaign feeding INC/Lynx ransomware. OSFI B-13 patch, access-control, and third-party-risk expectations apply to federally regulated financial institutions reviewing FortiGate MFA posture and privileged remote-access tooling (T6).
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1 · T3 · T4BOD 26-04 pile-up: ColdFusion, Langflow, Joomla due 10 July
Three KEV batches share a single federal deadline in the same week. Boards should treat BOD 26-04 as the external citation for emergency change control on internet-facing app servers, AI orchestration, and public CMS extensions — not a staggered backlog.
- T2Ivanti Sentry — unauth root RCE, KEV carry-forward
CVE-2026-10520 (CVSS 10, ~99% EPSS) has been KEV-listed since 11 June with Shadowserver-observed exploitation and backdoors, carrying into the July window; companion CVE-2026-10523 adds unauthenticated admin creation. The edge appliance belongs on the same disconnect-or-patch clock as the BOD 26-04 batch, not a June backlog item.
- T5 · T8Credential ransomware + Canadian public-sector pressure
FortiBleed feeds INC/Lynx with stolen VPN credentials while Mount Royal confirms Alberta FOIP-facing exfiltration and Winkler closes municipal offices. The programme question is whether MFA, immutable file-share backups, and provincial privacy playbooks are evidenced — before the next claim.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T5FortiBleed — ~110M credentials feeding INC / Lynx
SOCRadar links FortiGate VPN/auth sniffers to INC and Lynx negotiation panels (~430K targeted; ~11K still compromised after notify). Enforce MFA and rotate credentials — no CVE patch closes this campaign.
- T8Mount Royal — H-drive exfil under Alberta FOIP
University confirmed H-drive theft and deletion; CMD Organization claims ~30 BTC / ~$1.9M. Peer pressure: City of Winkler, Manitoba closed offices after a cybersecurity incident 8–9 July.
Structural control deficiencies revealed by the day's threats, independent of any single exploit.
- T3AI orchestration outside the ISO 42001 register
A second Langflow KEV (IDOR → credential harvest) after JadePuffer shows agent workflow platforms need inventory, exposure controls, and ownership under A.4.4 / A.6.2.6 / A.10.3 — not only CVE tickets.
- T6PAM / remote-support on a slower clock than VPN
BeyondTrust RS/PRA CVSS 4.0 9.2 flaws with cloud patched in April leave self-hosted ≤25.3.2 exposed. Privileged remote access needs the same emergency SLA as edge appliances before weaponization.
- T5No-CVE campaigns ignored by vulnerability process
FortiBleed has no vendor CVE — MFA gaps and unrotated VPN credentials are the control failure. Vulnerability management that only acts on CVE IDs misses credential ransomware pipelines.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1 · T3 · T4BOD 26-04 pile-up: ColdFusion, Langflow, Joomla due 10 July
Three KEV batches share a single federal deadline in the same week. Boards should treat BOD 26-04 as the external citation for emergency change control on internet-facing app servers, AI orchestration, and public CMS extensions — not a staggered backlog.
- T5 · T8Credential ransomware + Canadian public-sector pressure
FortiBleed feeds INC/Lynx with stolen VPN credentials while Mount Royal confirms Alberta FOIP-facing exfiltration and Winkler closes municipal offices. The programme question is whether MFA, immutable file-share backups, and provincial privacy playbooks are evidenced — before the next claim.
Remediation Actions
Consolidated actions across all eight threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1Apply Adobe APSB26-68 (ColdFusion 2025 Update 10 / 2023 Update 21); disable unauthenticated RDS; hunt for webshells on instances patched after 7 July.
- T2Upgrade Ivanti Sentry to R10.5.2 / R10.6.2 / R10.7.1 or disconnect; hunt for unauthorized admins and Shadowserver-class backdoors.
- T3T4Upgrade Langflow to 1.9.1 and Joomla SP Page Builder / Page Builder CK to 6.6.2 / 3.6.0; remove public exposure; meet BOD 26-04 (10 July) or document exceptions.
7 days
Short-term hardening
- T5Enforce MFA on all FortiGate VPN/admin paths; rotate credentials that traversed FortiGate auth; hunt for backdoor username adminin and config tampering.
- T6Upgrade self-hosted BeyondTrust RS/PRA to 25.3.3+; confirm cloud received the 21 April 2026 patch; review whether the exploit-required auth config is enabled.
- T7Deploy kernel updates with commit 81ccda30b4e8 and CVE-2026-46113 fixes on KVM hosts; remove world-writable /dev/kvm where present.
14 – 30 days
Programme remediation
- T3Add every Langflow / AI orchestration deployment to the ISO 42001 system register with network exposure controls and a named owner (A.4.4, A.6.2.6, A.10.3).
- T4Inventory public CMS estates for Joomla page-builder extensions; assign emergency patch owners; audit for hidden admins and PHP file managers.
- T8Test immutable restore of H-drive–class file shares; rehearse Alberta FOIP / provincial privacy notification with counsel; scope passport-class document storage.
Ongoing
Structural controls
- T1T2Keep ColdFusion and Ivanti Sentry on the same emergency disconnect-or-patch SLA as VPN concentrators — with RDS/auth-config evidence required in change records.
- T5Treat no-CVE credential campaigns as first-class incidents: MFA coverage metrics, post-notification compromise verification, and edge integrity monitoring.
- T6T7Govern PAM/remote-support and KVM hypervisor fleets with named owners, seven-day critical SLAs, and pre-weaponization upgrade windows.
Provenance
Intelligence Sources
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →