Adobe, Microsoft, and Kaseya Vulnerabilities Addressed
Critical RCEs in Adobe ColdFusion and Windows Deployment Services patched, alongside exploited Kaseya VSA flaws.

A critical remote code execution vulnerability in Adobe ColdFusion (CVE-2026-48362) has been patched. This flaw, rated CVSS 10.0, allows attackers to execute arbitrary code by exploiting an OS Command Injection vulnerability. Adobe has released updates to address this and other critical flaws in ColdFusion and Campaign Classic, urging immediate patching. The vulnerability could impact confidentiality, integrity, and availability. As Cyber Security News reported, this is a significant threat that requires prompt attention from all users of affected Adobe products.
Microsoft's August Patch Tuesday addresses a critical use-after-free vulnerability in Windows Deployment Services (CVE-2026-62893). This flaw allows an unauthorized attacker to execute code over a network. Microsoft has released updates to fix this and a total of 421 vulnerabilities, including a zero-day exploited in the wild. The Hacker News and SecurityWeek highlighted the severity of the vulnerabilities patched, with particular emphasis on the actively exploited zero-day.
Several critical vulnerabilities have been disclosed in Kaseya VSA, with CVE-2021-30116 allowing credential disclosure and CVE-2021-30120 enabling a bypass of two-factor authentication. These flaws, affecting versions before 9.5.7, were reportedly exploited in the wild in July 2021. The credential disclosure vulnerability could lead to unauthorized access, while the 2FA bypass undermines a critical security control. Prompt patching is essential to mitigate these risks.
A critical SQL injection vulnerability in SiYuan Note (CVE-2026-72811) affects versions up to v3.7.2. The flaw lies in the backlink/mention search query, where user-supplied keywords are concatenated into SQL queries without proper sanitization, potentially leading to unauthorized data access or modification. This vulnerability underscores the importance of secure coding practices in handling user input, especially in database interactions.
Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP2) is vulnerable to arbitrary file uploads or code execution due to insufficient input restrictions in RadAsyncUpload (CVE-2017-11357). This critical flaw allows remote attackers to compromise systems by uploading malicious files or executing arbitrary code. Users are advised to update to a patched version to prevent exploitation.
Multiple vulnerabilities in Adobe ColdFusion (CVE-2010-2861, CVE-2026-48362) allow for directory traversal and arbitrary code execution. Versions 9.0.1 and earlier are affected by directory traversal, while a separate OS Command Injection vulnerability (CVE-2026-48362) allows for arbitrary code execution. Adobe has released patches for these critical issues, and users should apply them immediately to protect their environments. The Hacker News detailed the severity of these flaws.
Critical vulnerabilities in Microsoft Windows, specifically CVE-2017-0144 and CVE-2017-0145, related to the SMBv1 server, have been identified. These high-severity flaws could allow remote attackers to gain privileges or execute arbitrary code. While older, these vulnerabilities highlight the persistent risks associated with legacy protocols. Users are strongly encouraged to disable SMBv1 and ensure their systems are up-to-date. Tenable Blog and Dark Reading have discussed the broader implications of such vulnerabilities.
Adobe Flash Player versions 21.0.0.197 and earlier are susceptible to a critical vulnerability (CVE-2016-1019) that could lead to denial of service or arbitrary code execution. This flaw was exploited in the wild in April 2016. Given that Flash Player is end-of-life, users should ensure it is completely removed from their systems to eliminate this risk.
Microsoft Silverlight, in versions prior to 5.1.41212.0 (CVE-2016-0034) and 5.1.20125.0 (CVE-2013-0074), contains vulnerabilities related to pointer validation and negative offset handling during decoding. These flaws could allow remote attackers to execute arbitrary code or cause a denial of service. As Silverlight is also largely deprecated, removal is the most effective mitigation.
Older vulnerabilities in Microsoft Windows, including privilege escalation flaws in Win32k.sys (CVE-2015-1701) and kernel-mode drivers (CVE-2015-2546), were exploited in the wild. These vulnerabilities allowed local users to gain elevated privileges. Keeping Windows systems updated is crucial to protect against such privilege escalation attacks.
JBoss Enterprise Application Platform (EAP) versions 4.2 and 4.3 are affected by a vulnerability (CVE-2010-1428) in the Web Console that allows unauthorized access due to insufficient access control for certain HTTP methods. This could enable attackers to access sensitive information or perform unauthorized actions. Updating to patched versions is recommended.
Oracle Java Runtime Environment (JRE) has an unspecified critical vulnerability (CVE-2012-0507) affecting multiple older versions. This flaw could impact confidentiality, integrity, and availability. Users should ensure they are running the latest supported versions of Java and apply any available security patches.
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 contains a vulnerability (CVE-2024-27253) that could allow an authenticated user to bypass security logic and perform unauthorized activities. This highlights the importance of rigorous security testing and validation of access controls in enterprise software.
Grav CMS API plugin (getgrav/grav-plugin-api) versions before 1.0.13 have an API key scope bypass vulnerability (CVE-2026-72824), allowing less privileged users to access functionality intended for administrators. This could lead to unauthorized actions within the CMS.
OpenWrt's luci-app-openvpn has a path traversal vulnerability (CVE-2026-72841) that allows authenticated users to write arbitrary files outside the intended directory by manipulating the instance_name2 parameter during file uploads. This could lead to system compromise.
Adobe Reader and Acrobat versions 8.x before 8.2.1 and 9.x before 9.3.1 are affected by a denial of service or arbitrary code execution vulnerability (CVE-2010-0188). Users should update to the latest available versions to mitigate this risk.