Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)
Multi-Vendor Critical Patch Roundup (TL-2026-1403), also tracked as APSB26-68, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-07-16 and last reviewed 2026-07-19. It has no confirmed attribution, affects Mozilla Firefox, references 23 CVEs (CVE-2026-15718, CVE-2026-15719, CVE-2026-15764), maps to 38 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-1403
- Threat ID
- TL-2026-1403
- Also known as
- APSB26-68, APSB26-73, APSB26-74, VMSA-2026-0005, MFSA2026-67
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-16
- Last reviewed
- 2026-07-19
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, retail, ecommerce, health, critical infrastructure
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-07-19 · 2 updates · revalidated 2× · latest source
A coordinated wave of vendor security updates addresses critical flaws across Firefox (public exploit code for 2 CVEs), Chrome (2 critical Ozone use-after-free bugs), Adobe (12 CVEs across ColdFusion, Commerce/Magento, and Experience Manager, several CVSS >= 9.0 including one CVSS 10.0), and Broadcom/VMware's Avi Load Balancer (CVSS 9.8 unauthenticated control-plane authentication bypass discovered by NATO's Cyber Security Centre). No CVE in this batch is confirmed as actively exploited in the wild or added to CISA KEV as of this report.
How Multi-Vendor Critical Patch Roundup works
On 2026-07-01 through 2026-07-14, four major vendors released overlapping critical security updates, creating a compressed patch window for enterprise defenders. Mozilla shipped Firefox 152.0.6 (MFSA2026-67) fixing CVE-2026-15718 (invalid pointer in the JavaScript: WebAssembly engine) and CVE-2026-15719 (a site-isolation bypass in DOM: Navigation); Mozilla explicitly confirmed public exploit code exists for both but found no evidence of in-the-wild attacks. Google shipped Chrome 150.0.7871.124/125 fixing 15 flaws including two critical use-after-free bugs in Ozone (CVE-2026-15764, CVE-2026-15765), Chrome's Linux windowing/display abstraction layer; both require a victim to perform specific UI gestures on a crafted HTML page and can lead to heap corruption and potential remote code execution, alongside 12 high-severity bugs in Skia, Libyuv, V8, Media, GPU, and Core. Adobe released three parallel bulletins: APSB26-68 for ColdFusion, patching 8 critical flaws (CVE-2026-48318 CVSS 9.9 path traversal to RCE; CVE-2026-48322 CVSS 9.6 code injection; CVE-2026-48284 CVSS 9.6 improper input validation; CVE-2026-48321 CVSS 9.3 incorrect authorization/privesc; CVE-2026-48325 CVSS 9.3 missing authentication to RCE; CVE-2026-48319 CVSS 9.1 path traversal; CVE-2026-48324 CVSS 9.1 SQL injection to RCE; CVE-2026-48327 CVSS 9.0 incorrect authorization) remediated in ColdFusion 2025 Update 11 and 2023 Update 22; APSB26-73 for Adobe Commerce/Magento Open Source, patching CVE-2026-48358 (NVD-rated CVSS 10.0, unauthenticated zero-interaction improper output escaping in the webhooks component leading to arbitrary code execution) and CVE-2026-48356 (CVSS 9.6, arbitrary file upload to privilege escalation), affecting every supported 2.4.x line; and APSB26-74 for Adobe Experience Manager, patching CVE-2026-48259 (CVSS 9.6 SSRF to RCE) and CVE-2026-48359 (CVSS 9.6 XXE to RCE), both credited to Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote. Finally, Broadcom published VMSA-2026-0005 for VMware Avi Load Balancer, addressing seven vulnerabilities (CVE-2026-47865 through CVE-2026-47871) spanning authentication bypass, remote code execution, privilege escalation, and directory traversal; the headline flaw, CVE-2026-47865 (CVSS 9.8), allows a network-positioned attacker with no credentials to bypass authentication and reach the Avi control plane, and was discovered by Filip Waeytens of NATO's technology and cyber hub. None of the 17 CVEs tracked in this roundup carries a confirmed in-the-wild exploitation report or CISA KEV listing at time of writing; the hunt rationale qualifies the cluster purely on CVSS/network-vector severity and the compressed multi-vendor patch timing that raises near-term weaponization risk, particularly for the unauthenticated ColdFusion, Commerce webhooks, and Avi Load Balancer flaws.
MITRE ATT&CK techniques used in TL-2026-1403
Collection
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1614 System Location Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1211 Exploitation for Stealth; T1497 Virtualization/Sandbox Evasion
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1078 Valid Accounts; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.002 Phishing: Spearphishing Link
Persistence
T1136 Create Account; T1505 Server Software Component
Lateral Movement
T1210 Exploitation of Remote Services
Credential Access
T1212 Exploitation for Credential Access
Impact
T1489 Service Stop; T1498 Network Denial of Service; T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1565 Data Manipulation
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1584.006 Compromise Infrastructure: Web Services; T1587 Develop Capabilities
Reconnaissance
T1592.004 Gather Victim Host Information: Client Configurations; T1593 Search Open Websites/Domains; T1595 Active Scanning
defense-impairment
Affected products and versions in Multi-Vendor Critical Patch Roundup
- Mozilla — Firefox
Vulnerable versions: prior to 152.0.6; Firefox for iOS prior to 152.4
Fixed in: 152.0.6; 152.4 (iOS) - Google — Chrome
Vulnerable versions: prior to 150.0.7871.124/125
Fixed in: 150.0.7871.124 (Windows/Linux); 150.0.7871.125 (Windows/macOS) - Adobe — ColdFusion
Vulnerable versions: 2025 prior to Update 11; 2023 prior to Update 22
Fixed in: 2025 Update 11; 2023 Update 22 - Adobe — Commerce / Magento Open Source
Vulnerable versions: all supported 2.4.x lines prior to APSB26-73 patch
Fixed in: patched 2.4.x per APSB26-73 - Adobe — Experience Manager
Vulnerable versions: versions prior to APSB26-74 patch
Fixed in: patched per APSB26-74 - Broadcom / VMware — Avi Load Balancer
Vulnerable versions: prior to 31.2.2
Fixed in: 31.2.2
Remediation for Multi-Vendor Critical Patch Roundup
Patches
- Firefox 152.0.6 (MFSA2026-67)
- Chrome 150.0.7871.124/125 (stable channel)
- ColdFusion 2025 Update 11 / 2023 Update 22 (APSB26-68)
- Adobe Commerce/Magento Open Source patch (APSB26-73)
- Adobe Experience Manager patch (APSB26-74)
- Avi Load Balancer 31.2.2 or later per VMSA-2026-0005
Immediate actions
- Update Firefox to 152.0.6 or later (152.4+ for Firefox for iOS)
- Update Chrome to 150.0.7871.124/125 or later on all platforms
- Apply Adobe ColdFusion 2025 Update 11 or 2023 Update 22 immediately, prioritizing internet-facing instances
- Apply Adobe Commerce/Magento Open Source patches from APSB26-73 to all supported 2.4.x lines, prioritizing the webhooks-related CVE-2026-48358
- Apply Adobe Experience Manager patches from APSB26-74
- Patch VMware Avi Load Balancer per VMSA-2026-0005 and restrict management-plane network access as an interim compensating control
- Inventory all instances of ColdFusion, Commerce/Magento, AEM, and Avi Load Balancer exposed to the internet or partner networks
Workarounds
- Restrict network access to Avi Load Balancer control plane pending patch
- Disable or restrict Adobe Commerce webhooks functionality where not required
- Restrict inbound access to ColdFusion administrative endpoints
Longer-term hardening
- Segment load-balancer and application-server management planes from general network access
- Establish accelerated patch SLAs for internet-facing Adobe and VMware infrastructure given historical weaponization speed of these product lines
- Deploy EDR/WAF virtual patching for ColdFusion and Commerce deployments pending patch rollout
- Enable browser auto-update policies enterprise-wide for Firefox and Chrome fleets
- Monitor CISA KEV and vendor advisories for escalation of any of these 17 CVEs to confirmed active exploitation
CVEs associated with Multi-Vendor Critical Patch Roundup
- CVE-2026-15718
- CVE-2026-15719
- CVE-2026-15764
- CVE-2026-15765
- CVE-2026-48318
CVE-2026-48322CVE-2026-48284CVE-2026-48321CVE-2026-48325CVE-2026-48319CVE-2026-48324CVE-2026-48327CVE-2026-48356CVE-2026-48358CVE-2026-48259CVE-2026-48359CVE-2026-47865CVE-2026-47866CVE-2026-47867CVE-2026-47868CVE-2026-47869CVE-2026-47870CVE-2026-47871
Weaknesses (CWE) in Multi-Vendor Critical Patch Roundup
CWE-822, CWE-284, CWE-416, CWE-22, CWE-94, CWE-20, CWE-863, CWE-306, CWE-89, CWE-434
Timeline of Multi-Vendor Critical Patch Roundup
- The Hacker News publishes a consolidated roundup covering all four vendors' updates, noting no confirmed in-the-wild exploitation or CISA KEV listing for any covered CVE.
- Mozilla ships Firefox 152.0.6 (MFSA2026-67), patching CVE-2026-15718 and CVE-2026-15719; Mozilla confirms public exploit code exists for both.
- Adobe publishes APSB26-68, patching 8 critical ColdFusion vulnerabilities including CVE-2026-48318 (CVSS 9.9).
- Google ships Chrome 150.0.7871.124/125 stable channel update, patching two critical Ozone use-after-free bugs (CVE-2026-15764, CVE-2026-15765) plus 12 high-severity issues.
- Analyst write-ups credit Filip Waeytens of NATO's Cyber Security Centre (CVE-2026-47865/-47866/-47867/-47868) and Lang Khuong Duy of Viettel IDC (CVE-2026-47869/-47870/-47871) as the reporting researchers, and confirm no workaround exists for any of the seven Avi Load Balancer CVEs — patching to 32.1.2, 31.2.2-2p3, or 30.2.7 is mandatory.
- Adobe publishes APSB26-74 for Experience Manager, patching CVE-2026-48259 and CVE-2026-48359 (both CVSS 9.6), credited to Assetnote researchers.
- Adobe publishes APSB26-73 for Commerce/Magento Open Source, patching CVE-2026-48358 (NVD CVSS 10.0) and CVE-2026-48356 (CVSS 9.6).
- Qualys ThreatPROTECT publishes analysis of CVE-2026-15718/CVE-2026-15719, mapping them to QID 387870 for vulnerability scanning.
- HKCERT issues High Threat Security Alert A26-07-22 specifically on the Firefox MFSA2026-67 flaws (CVE-2026-15718, CVE-2026-15719), urging immediate patching due to public PoC availability.
- Heise (Germany) publishes coverage of the VMware Avi Load Balancer authentication bypass, extending awareness into European enterprise/DACH-region readership.
- Broadcom publishes VMSA-2026-0005 for VMware Avi Load Balancer, patching 7 vulnerabilities including CVE-2026-47865 (CVSS 9.8 authentication bypass), discovered by Filip Waeytens of NATO's Cyber Security Centre.
- Hong Kong CERT (HKCERT) issues Security Alert A26-07-28 referencing the Broadcom VMSA-2026-0005 advisory, indicating propagation to national/regional CERT distribution lists.
- TL-Intel Harness flags the roundup for tracking based on CVSS/network-vector criteria across all four vendors.
- As of this report, neither CVE-2026-15718 nor CVE-2026-15719 appears in the CISA KEV catalog; NVD/CISA-ADP scores them 4.3 and 5.4 respectively (CVSS 3.1).
Update history for TL-2026-1403
- 2026-07-19 — Multiple Firefox Vulnerabilities Enable RCE/DoS/Security Bypass with Public Exploits (CVE-2026-15718, CVE-2026-15719): What changed No field escalation — Firefox-specific NVD scores (4.3/5.4) are lower than the roundup's aggregate 9.9 and do not override it. Root-cause CWEs (CWE-763, CWE-200) newly captured for the Firefox CVEs. New indicators (5) Added HKC
- 2026-07-19 — Critical Authentication Bypass in VMware Avi Load Balancer (CVE-2026-47865, CVSS 9.8) Leads Seven-Flaw Patch Batch (VMSA-2026-0005): What changed No field escalations — this roundup's overall severity/CVSS (9.9) and exploitability (POC_PUBLIC) are already driven by the Firefox component and remain the ceiling for the multi-vendor record; the Avi Load Balancer sub-compone
Sources cited for Multi-Vendor Critical Patch Roundup
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
- Security Vulnerabilities fixed in Firefox 152.0.6 (MFSA2026-67)
- Chrome Releases: Stable Channel Update for Desktop
- Adobe Security Bulletin APSB26-68 (ColdFusion)
- Security update available for Adobe Commerce - APSB26-73
- Adobe Security Bulletin APSB26-74 (Experience Manager)
- 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
- Support Content Notification (VMSA-2026-0005)
- VMware Avi Load Balancer Vulnerabilities Let Attackers Bypass Authentication
- Chrome 150 Security Update Patches 15 Flaws, Including Two Critical Code Execution Ones
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
- Adobe Patches Critical ColdFusion Vulnerabilities
- Adobe Releases Patches for ColdFusion Critical Vulnerabilities - Qualys ThreatPROTECT
- Release Notes for Avi Load Balancer Version 31.2.2
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
Threats related to Multi-Vendor Critical Patch Roundup
- Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution (CVE-2026-48449) Paired With SQL Injection Memory/File Disclosure (CVE-2026-48448)
- Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)
- Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282)
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution
Detection coverage for TL-2026-1403
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1403 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.