Security Roundup: Adobe ColdFusion CVSS 10 Wave, SharePoint Warlock Ransomware, LoadMaster Pre-Auth RCE, Argo CD Kubernetes Zero-Auth — Week of July 3, 2026
Weekly briefing: Adobe ColdFusion 6x CVSS 10.0 wave, SharePoint Warlock ransomware, and Cursor IDE DuneSlide prompt injection.
A week dominated by six simultaneous CVSS 10.0 remote code execution flaws in Adobe ColdFusion — the largest single-update max-severity Adobe release on record — alongside a Microsoft SharePoint deserialization vulnerability now actively weaponized by Storm-2603 to deploy Warlock ransomware, a pre-authentication OS command injection in Progress Kemp LoadMaster with public exploitation commencing just four days after the watchTowr write-up dropped, a critical Argo CD repo-server flaw that has been open for eighteen months with no CVE and no patch, and a pair of CVSS 9.8 prompt-injection-to-RCE flaws in the Cursor AI code editor affecting more than half the Fortune 500. Here is everything you need to know and act on.
1. Adobe ColdFusion — Six CVSS 10.0 RCEs in One Update (CVE-2026-48276, 48277, 48281, 48282, 48283, 48316)
On July 1, 2026, Adobe released an emergency out-of-cycle security bulletin (APSB26-68) for ColdFusion 2025 and ColdFusion 2023 addressing eleven vulnerabilities, six of which carry the maximum CVSS score of 10.0. All six enable unauthenticated remote code execution — no credentials, no interaction required.
The six CVSS 10.0 flaws break into two root-cause classes: CVE-2026-48276 and CVE-2026-48283 (CWE-434, unrestricted file upload) allow a POST to a ColdFusion endpoint to write and execute a malicious file directly on the server without authentication. CVE-2026-48277, CVE-2026-48281, and CVE-2026-48316 (CWE-20, improper input validation) achieve OS command injection through unsanitized request parameters passed to built-in ColdFusion service handlers. CVE-2026-48282 (CWE-22, path traversal) escapes the configured upload directory and writes an executable template to a web-accessible location.
Affected: ColdFusion 2025 ≤ Update 9; ColdFusion 2023 ≤ Update 20. Fixed: ColdFusion 2025 Update 10; ColdFusion 2023 Update 21. Exploitation: No confirmed in-the-wild exploitation as of July 2 — but ColdFusion has historically been weaponized within 24–72 hours of patch publication (CVE-2023-26360 took 8 days).
Action: Apply updates immediately. Block port 8500 (CF admin) to trusted IPs only. Scan web root for unexpected .cfm and .jsp files.
2. CVE-2026-45659 — SharePoint RCE Weaponized by Storm-2603 / Warlock Ransomware: CISA KEV, Federal Deadline July 4
CVE-2026-45659 (CVSS 8.8) is a deserialization of untrusted data flaw in Microsoft SharePoint Server (Subscription Edition, 2019, 2016 Enterprise). Patched in May 2026 Patch Tuesday, a PoC surfaced shortly after. CISA added it to the KEV catalog this week with a federal remediation deadline of July 4, 2026. Active exploitation has been attributed to Storm-2603, a financially motivated threat cluster deploying Warlock ransomware against on-premises SharePoint deployments.
Attack chain: Any authenticated SharePoint user — minimum Site Member permissions — can send a crafted HTTP POST with a malicious serialized .NET object to a vulnerable API endpoint. SharePoint deserializes it using BinaryFormatter, executing code as the application pool service account. Storm-2603 follows with credential dumping (Mimikatz), lateral movement (BloodHound CE), and Warlock ransomware deployment — ChaCha20 file encryption, double extortion, C2 over Tor.
Action: Apply KB5002694 (SharePoint 2019) / KB5002695 (SharePoint 2016 Enterprise) immediately. Restrict internet-facing SharePoint access to VPN if patching is delayed. Hunt for WARLOCK_RESTORE.txt, unexpected scheduled tasks, and outbound Tor connections from SharePoint servers.
3. CVE-2026-8037 — Progress Kemp LoadMaster Pre-Auth RCE: CVSS 9.6, Active Exploitation Since June 29
CVE-2026-8037 (CVSS 9.6) is an unauthenticated OS command injection in Progress Kemp LoadMaster. The root cause is a C function named escape_quotes() that sanitizes API input before passing it to shell commands, but fails to null-terminate its output buffer — causing an out-of-bounds read into adjacent heap memory that attacker-controlled request data can populate. The vulnerable endpoint is /accessv2; successful exploitation achieves root-level RCE, since the API service runs as root.
watchTowr Labs published a full technical breakdown and PoC on June 29, 2026. eSentire TRU confirmed exploitation attempts began the same day. A working PoC is public.
Affected: GA ≤ v7.2.63.1; LTSF ≤ v7.2.54.17 (API enabled). Fixed: GA v7.2.63.2; LTSF v7.2.54.18. Action: Patch immediately. If delayed, disable the LoadMaster API (System Configuration → API Security → Disable) and restrict management interfaces to trusted IP ranges.
4. Argo CD Repo-Server — Zero-Auth RCE: 18 Months Unpatched, Full Kubernetes Cluster Takeover
Synacktiv publicly disclosed an unpatched zero-authentication RCE in Argo CD's repo-server on July 1, 2026 — a vulnerability reported to maintainers in January 2025 that remains unaddressed. There is no CVE. There is no patch.
Attack chain: Argo CD's repo-server gRPC service (port 8081) has no authentication. An attacker with network access sends a crafted gRPC request abusing kustomize's --helm-command option to execute an arbitrary binary, achieving RCE in the repo-server pod. The pod's environment exposes REDIS_PASSWORD, which the attacker uses to connect to Argo CD's Redis cache, poison the stored Kubernetes manifests, and cause Argo CD's next automatic sync to deploy attacker-controlled workloads across the cluster.
No patch exists. Mitigation: Apply Kubernetes NetworkPolicy to restrict repo-server (port 8081) and Redis (port 6379) to Argo CD components only. Argo CD provides policy YAML files; Helm chart users must explicitly enable them with networkPolicies.enabled=true.
5. DuneSlide — CVE-2026-50548 / CVE-2026-50549: CVSS 9.8 Prompt Injection to Sandbox Escape and RCE in Cursor IDE
Cato AI Labs disclosed DuneSlide — two CVSS 9.8 flaws (CVSS 4.0: 9.3) in Cursor IDE that convert prompt injection into full host RCE with no user interaction. All Cursor versions before 3.0 are vulnerable; Cursor claims adoption by more than half the Fortune 500.
CVE-2026-50548 abuses Cursor's working_directory command parameter: the AI agent is instructed to run a command with working_directory pointing to a sensitive system path (e.g., /Applications/Cursor.app/.../helpers/), which Cursor adds to its write allow-list without validation, enabling the agent to overwrite the sandbox enforcement binary itself — eliminating the sandbox for all subsequent commands.
CVE-2026-50549 abuses symlink resolution: when Cursor's pre-write symlink check fails (target doesn't exist or a directory has restricted read permissions), it falls back to trusting the unresolved path — writing wherever the symlink points outside the project root.
Both chains trigger via poisoned content ingested during a normal AI prompt — an MCP server response, web search result, or document opened in the IDE. Fixed: Cursor 3.0 (April 2, 2026). Action: Update immediately. Disable agentic terminal access until updated.
Deep Dives
For full technical analysis, attack chain breakdowns, IOCs, and remediation commands, see the individual deep-dive posts:
- Adobe ColdFusion: Six CVSS 10.0 RCEs in One Update — CVE-2026-48276, 48277, 48281, 48282, 48283, 48316
- CVE-2026-45659: Microsoft SharePoint RCE Weaponized by Storm-2603 Warlock Ransomware — CISA KEV, Federal Deadline July 4
- CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE — escape_quotes() Heap Failure, Active Exploitation
- Argo CD Repo-Server: 18-Month Unpatched Zero-Auth RCE Enables Full Kubernetes Cluster Takeover
- DuneSlide: CVE-2026-50548 / CVE-2026-50549 — Zero-Click Prompt Injection to RCE in Cursor IDE