Weekly Cyber Threat Report (July 7–15, 2026): ColdFusion RCE, Record Patch Tuesday & API Attacks

Weekly Cyber Threat Report ColdFusion RCE, Record Patch Tuesday & API Attacks

Table of Contents

Share Article

The Week in one line

The week of July 7–15, 2026 brought Microsoft’s largest-ever patch cycle, an actively exploited maximum-severity ColdFusion flaw, a nation-state campaign against university research networks, and fresh data confirming the shift security teams already feel: the attack surface has moved to the application and API layer, and it’s now automated on both sides. Here’s what mattered and what to do about it.
Key takeaways:

Critical CVEs actively exploited (July 7-15, 2026)

Here’s the week’s critical-CVE picture at a glance, then the detail that matters.
Adobe ColdFusion — path traversal to RCE (CVE-2026-48282, CVSS 10.0). A maximum-severity path traversal flaw in ColdFusion is under active exploitation, letting attackers drop malicious files into web-accessible directories and achieve full remote code execution. It was one of several perfect-10 ColdFusion flaws disclosed in the same window as evidence of sustained, automated scanning against internet-facing instances. CISA added it to the Known Exploited Vulnerabilities catalog on July 7 with a federal patch deadline of July 10.
Gitea – authentication bypass in self-hosted Git (CVE-2026-20896, CVSS 9.8). A default wildcard trust configuration (REVERSE_PROXY_TRUSTED_PROXIES=*) allows any source IP to impersonate an authenticated user, including administrators. Threat actors began probing installations roughly 13 days after disclosure, a reminder that “self-hosted and internal” is not the same as “unreachable.”
BeyondTrust – privileged access flaws (CVE-2026-40138 + CVE-2026-40139, CVSS 9.2 each). Two critical pre-authentication vulnerabilities in Remote Support and Privileged Remote Access software were patched this week. No confirmed in-the-wild exploitation yet, but researchers flagged the pair as a worst-case scenario for privileged-access infrastructure: full compromise without valid credentials.
SAP NetWeaver — memory corruption (CVSS 9.9) An out-of-bounds write in the ERP platform lets an authenticated attacker corrupt memory and read or modify sensitive business-critical data.

July 2026 Patch Tuesday: a record 570-CVE cycle

Microsoft’s July 2026 Patch Tuesday was its largest ever: 570 vulnerabilities by Microsoft’s own count (some trackers count 622 across all associated CVEs), including three zero-days — two already under active exploitation. Notably, Microsoft attributed the unprecedented volume in part to an AI-powered vulnerability-discovery system it recently deployed to find flaws before attackers do. That’s the theme of 2026 in one release: AI is now scaling both discovery and exploitation, and defenders can’t triage a cycle this large by hand. Prioritize internet-facing and known-exploited (KEV) bugs first.

Notable data breaches this week: Accenture & nation-state intrusions

APIs and bots: the primary attack surface in 2026

Beneath the CVE headlines, the structural data tells the bigger story and it’s backed by 2026 primary research, not vibes:
This week is a microcosm of a shift that’s been building all year: the attack surface has moved from the network edge to the application and API layer, and it’s automated on both sides. Attackers use AI-driven bots and coordinated botnets to probe, exploit, and flood applications faster than manual defense teams can respond. Meanwhile, defenders still run fragmented stacks: a WAF here, a bot filter there, DDoS scrubbing somewhere else with no unified visibility across any of it. That fragmentation is the real vulnerability.

How unified WAAP protection addresses these threats

Prophaze exists for exactly this shift. Instead of stitching together separate tools for WAF, API security, bot management, and DDoS mitigation, Prophaze delivers all four as a single, AI-driven WAAP (Web Application and API Protection) platform:
The threats in this digest aren’t outliers. They’re this week’s version of a pattern that repeats every week. The organizations that stay ahead of it are the ones consolidating defense into a single, adaptive platform now – rather than reacting incident by incident.

See how virtual patching closes the exposure window on CVEs like these → [Explore Prophaze WAAP] Prefer it in your inbox? Get this digest every week → [Subscribe to Prophaze Threat Intel]

Frequently Asked Questions (FAQ)

1. What is a WAAP and how is it different from a traditional WAF?
A WAAP (Web Application and API Protection) platform combines WAF, API security, bot management, and DDoS mitigation into a single unified layer, versus a traditional WAF which only filters known web application attack signatures.

APIs often expose sensitive data with limited monitoring, and attackers now favor behavior-based abuse (scraping, credential stuffing, business-logic exploitation) that bypasses traditional signature-based defenses.

Virtual patching blocks exploitation of a known vulnerability at the WAAP/WAF layer before an official software patch is applied or deployed, reducing the exposure window.

You May Also Like

Weekly Cyber Threat Report ColdFusion RCE, Record Patch Tuesday & API Attacks

Weekly Cyber Threat Report (July 7–15, 2026): ColdFusion RCE, Record Patch Tuesday & API Attacks

The Week in one line The week of July 7–15, 2026 brought Microsoft’s largest-ever patch

FIFA World Cup 2026 Final

FIFA World Cup 2026 Final: The Cyberattacks Hiding Behind the Biggest Match on Earth

In two days, the planet’s attention turns to MetLife Stadium for Spain vs Argentina, the

DNS Security for Smart Grids and Digital Utilities

DNS Security for Smart Grids and Digital Utilities: Why It Matters More Than Ever

DNS security for smart grids is the practice of monitoring, filtering, and defending the Domain

Scroll to Top