Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)

Multi-Vendor Critical Patch Roundup (TL-2026-1403), also tracked as APSB26-68, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-07-16 and last reviewed 2026-07-19. It has no confirmed attribution, affects Mozilla Firefox, references 23 CVEs (CVE-2026-15718, CVE-2026-15719, CVE-2026-15764), maps to 38 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-1403

Threat ID
TL-2026-1403
Also known as
APSB26-68, APSB26-73, APSB26-74, VMSA-2026-0005, MFSA2026-67
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-16
Last reviewed
2026-07-19
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, retail, ecommerce, health, critical infrastructure
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
28
Updates
2026-07-19 · 2 updates · revalidated 2× · latest source

A coordinated wave of vendor security updates addresses critical flaws across Firefox (public exploit code for 2 CVEs), Chrome (2 critical Ozone use-after-free bugs), Adobe (12 CVEs across ColdFusion, Commerce/Magento, and Experience Manager, several CVSS >= 9.0 including one CVSS 10.0), and Broadcom/VMware's Avi Load Balancer (CVSS 9.8 unauthenticated control-plane authentication bypass discovered by NATO's Cyber Security Centre). No CVE in this batch is confirmed as actively exploited in the wild or added to CISA KEV as of this report.

How Multi-Vendor Critical Patch Roundup works

On 2026-07-01 through 2026-07-14, four major vendors released overlapping critical security updates, creating a compressed patch window for enterprise defenders. Mozilla shipped Firefox 152.0.6 (MFSA2026-67) fixing CVE-2026-15718 (invalid pointer in the JavaScript: WebAssembly engine) and CVE-2026-15719 (a site-isolation bypass in DOM: Navigation); Mozilla explicitly confirmed public exploit code exists for both but found no evidence of in-the-wild attacks. Google shipped Chrome 150.0.7871.124/125 fixing 15 flaws including two critical use-after-free bugs in Ozone (CVE-2026-15764, CVE-2026-15765), Chrome's Linux windowing/display abstraction layer; both require a victim to perform specific UI gestures on a crafted HTML page and can lead to heap corruption and potential remote code execution, alongside 12 high-severity bugs in Skia, Libyuv, V8, Media, GPU, and Core. Adobe released three parallel bulletins: APSB26-68 for ColdFusion, patching 8 critical flaws (CVE-2026-48318 CVSS 9.9 path traversal to RCE; CVE-2026-48322 CVSS 9.6 code injection; CVE-2026-48284 CVSS 9.6 improper input validation; CVE-2026-48321 CVSS 9.3 incorrect authorization/privesc; CVE-2026-48325 CVSS 9.3 missing authentication to RCE; CVE-2026-48319 CVSS 9.1 path traversal; CVE-2026-48324 CVSS 9.1 SQL injection to RCE; CVE-2026-48327 CVSS 9.0 incorrect authorization) remediated in ColdFusion 2025 Update 11 and 2023 Update 22; APSB26-73 for Adobe Commerce/Magento Open Source, patching CVE-2026-48358 (NVD-rated CVSS 10.0, unauthenticated zero-interaction improper output escaping in the webhooks component leading to arbitrary code execution) and CVE-2026-48356 (CVSS 9.6, arbitrary file upload to privilege escalation), affecting every supported 2.4.x line; and APSB26-74 for Adobe Experience Manager, patching CVE-2026-48259 (CVSS 9.6 SSRF to RCE) and CVE-2026-48359 (CVSS 9.6 XXE to RCE), both credited to Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote. Finally, Broadcom published VMSA-2026-0005 for VMware Avi Load Balancer, addressing seven vulnerabilities (CVE-2026-47865 through CVE-2026-47871) spanning authentication bypass, remote code execution, privilege escalation, and directory traversal; the headline flaw, CVE-2026-47865 (CVSS 9.8), allows a network-positioned attacker with no credentials to bypass authentication and reach the Avi control plane, and was discovered by Filip Waeytens of NATO's technology and cyber hub. None of the 17 CVEs tracked in this roundup carries a confirmed in-the-wild exploitation report or CISA KEV listing at time of writing; the hunt rationale qualifies the cluster purely on CVSS/network-vector severity and the compressed multi-vendor patch timing that raises near-term weaponization risk, particularly for the unauthenticated ColdFusion, Commerce webhooks, and Avi Load Balancer flaws.

MITRE ATT&CK techniques used in TL-2026-1403

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1211 Exploitation for Stealth; T1497 Virtualization/Sandbox Evasion

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.002 Phishing: Spearphishing Link

Persistence

T1136 Create Account; T1505 Server Software Component

Lateral Movement

T1210 Exploitation of Remote Services

Credential Access

T1212 Exploitation for Credential Access

Impact

T1489 Service Stop; T1498 Network Denial of Service; T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1565 Data Manipulation

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1584.006 Compromise Infrastructure: Web Services; T1587 Develop Capabilities

Reconnaissance

T1592.004 Gather Victim Host Information: Client Configurations; T1593 Search Open Websites/Domains; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Multi-Vendor Critical Patch Roundup

  • Mozilla — Firefox
    Vulnerable versions: prior to 152.0.6; Firefox for iOS prior to 152.4
    Fixed in: 152.0.6; 152.4 (iOS)
  • Google — Chrome
    Vulnerable versions: prior to 150.0.7871.124/125
    Fixed in: 150.0.7871.124 (Windows/Linux); 150.0.7871.125 (Windows/macOS)
  • Adobe — ColdFusion
    Vulnerable versions: 2025 prior to Update 11; 2023 prior to Update 22
    Fixed in: 2025 Update 11; 2023 Update 22
  • Adobe — Commerce / Magento Open Source
    Vulnerable versions: all supported 2.4.x lines prior to APSB26-73 patch
    Fixed in: patched 2.4.x per APSB26-73
  • Adobe — Experience Manager
    Vulnerable versions: versions prior to APSB26-74 patch
    Fixed in: patched per APSB26-74
  • Broadcom / VMware — Avi Load Balancer
    Vulnerable versions: prior to 31.2.2
    Fixed in: 31.2.2

Remediation for Multi-Vendor Critical Patch Roundup

Patches

  • Firefox 152.0.6 (MFSA2026-67)
  • Chrome 150.0.7871.124/125 (stable channel)
  • ColdFusion 2025 Update 11 / 2023 Update 22 (APSB26-68)
  • Adobe Commerce/Magento Open Source patch (APSB26-73)
  • Adobe Experience Manager patch (APSB26-74)
  • Avi Load Balancer 31.2.2 or later per VMSA-2026-0005

Immediate actions

  • Update Firefox to 152.0.6 or later (152.4+ for Firefox for iOS)
  • Update Chrome to 150.0.7871.124/125 or later on all platforms
  • Apply Adobe ColdFusion 2025 Update 11 or 2023 Update 22 immediately, prioritizing internet-facing instances
  • Apply Adobe Commerce/Magento Open Source patches from APSB26-73 to all supported 2.4.x lines, prioritizing the webhooks-related CVE-2026-48358
  • Apply Adobe Experience Manager patches from APSB26-74
  • Patch VMware Avi Load Balancer per VMSA-2026-0005 and restrict management-plane network access as an interim compensating control
  • Inventory all instances of ColdFusion, Commerce/Magento, AEM, and Avi Load Balancer exposed to the internet or partner networks

Workarounds

  • Restrict network access to Avi Load Balancer control plane pending patch
  • Disable or restrict Adobe Commerce webhooks functionality where not required
  • Restrict inbound access to ColdFusion administrative endpoints

Longer-term hardening

  • Segment load-balancer and application-server management planes from general network access
  • Establish accelerated patch SLAs for internet-facing Adobe and VMware infrastructure given historical weaponization speed of these product lines
  • Deploy EDR/WAF virtual patching for ColdFusion and Commerce deployments pending patch rollout
  • Enable browser auto-update policies enterprise-wide for Firefox and Chrome fleets
  • Monitor CISA KEV and vendor advisories for escalation of any of these 17 CVEs to confirmed active exploitation

CVEs associated with Multi-Vendor Critical Patch Roundup

Weaknesses (CWE) in Multi-Vendor Critical Patch Roundup

CWE-822, CWE-284, CWE-416, CWE-22, CWE-94, CWE-20, CWE-863, CWE-306, CWE-89, CWE-434

Timeline of Multi-Vendor Critical Patch Roundup

  • The Hacker News publishes a consolidated roundup covering all four vendors' updates, noting no confirmed in-the-wild exploitation or CISA KEV listing for any covered CVE.
  • Mozilla ships Firefox 152.0.6 (MFSA2026-67), patching CVE-2026-15718 and CVE-2026-15719; Mozilla confirms public exploit code exists for both.
  • Adobe publishes APSB26-68, patching 8 critical ColdFusion vulnerabilities including CVE-2026-48318 (CVSS 9.9).
  • Google ships Chrome 150.0.7871.124/125 stable channel update, patching two critical Ozone use-after-free bugs (CVE-2026-15764, CVE-2026-15765) plus 12 high-severity issues.
  • Analyst write-ups credit Filip Waeytens of NATO's Cyber Security Centre (CVE-2026-47865/-47866/-47867/-47868) and Lang Khuong Duy of Viettel IDC (CVE-2026-47869/-47870/-47871) as the reporting researchers, and confirm no workaround exists for any of the seven Avi Load Balancer CVEs — patching to 32.1.2, 31.2.2-2p3, or 30.2.7 is mandatory.
  • Adobe publishes APSB26-74 for Experience Manager, patching CVE-2026-48259 and CVE-2026-48359 (both CVSS 9.6), credited to Assetnote researchers.
  • Adobe publishes APSB26-73 for Commerce/Magento Open Source, patching CVE-2026-48358 (NVD CVSS 10.0) and CVE-2026-48356 (CVSS 9.6).
  • Qualys ThreatPROTECT publishes analysis of CVE-2026-15718/CVE-2026-15719, mapping them to QID 387870 for vulnerability scanning.
  • HKCERT issues High Threat Security Alert A26-07-22 specifically on the Firefox MFSA2026-67 flaws (CVE-2026-15718, CVE-2026-15719), urging immediate patching due to public PoC availability.
  • Heise (Germany) publishes coverage of the VMware Avi Load Balancer authentication bypass, extending awareness into European enterprise/DACH-region readership.
  • Broadcom publishes VMSA-2026-0005 for VMware Avi Load Balancer, patching 7 vulnerabilities including CVE-2026-47865 (CVSS 9.8 authentication bypass), discovered by Filip Waeytens of NATO's Cyber Security Centre.
  • Hong Kong CERT (HKCERT) issues Security Alert A26-07-28 referencing the Broadcom VMSA-2026-0005 advisory, indicating propagation to national/regional CERT distribution lists.
  • TL-Intel Harness flags the roundup for tracking based on CVSS/network-vector criteria across all four vendors.
  • As of this report, neither CVE-2026-15718 nor CVE-2026-15719 appears in the CISA KEV catalog; NVD/CISA-ADP scores them 4.3 and 5.4 respectively (CVSS 3.1).

Update history for TL-2026-1403

Sources cited for Multi-Vendor Critical Patch Roundup

Threats related to Multi-Vendor Critical Patch Roundup

Detection coverage for TL-2026-1403

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1403 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats