Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005) — Threadlinqs Intelligence
As of 2026-07-19, Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1403 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · 2 updates · revalidated 2× · latest source
A coordinated wave of vendor security updates addresses critical flaws across Firefox (public exploit code for 2 CVEs), Chrome (2 critical Ozone use-after-free bugs), Adobe (12 CVEs across ColdFusion,
On 2026-07-01 through 2026-07-14, four major vendors released overlapping critical security updates, creating a compressed patch window for enterprise defenders. Mozilla shipped Firefox 152.0.6 (MFSA2026-67) fixing CVE-2026-15718 (invalid pointer in the JavaScript: WebAssembly engine) and CVE-2026-15719 (a site-isolation bypass in DOM: Navigation); Mozilla explicitly confirmed public exploit code exists for both but found no evidence of in-the-wild attacks. Google shipped Chrome 150.0.7871.124/125 fixing 15 flaws including two critical use-after-free bugs in Ozone (CVE-2026-15764, CVE-2026-15765), Chrome's Linux windowing/display abstraction layer; both require a victim to perform specific UI gestures on a crafted HTML page and can lead to heap corruption and potential remote code execution, alongside 12 high-severity bugs in Skia, Libyuv, V8, Media, GPU, and Core. Adobe released three parallel bulletins: APSB26-68 for ColdFusion, patching 8 critical flaws (CVE-2026-48318 CVSS 9.9 path traversal to RCE; CVE-2026-48322 CVSS 9.6 code injection; CVE-2026-48284 CVSS 9.6 improper input validation; CVE-2026-48321 CVSS 9.3 incorrect authorization/privesc; CVE-2026-48325 CVSS 9.3 missing authentication to RCE; CVE-2026-48319 CVSS 9.1 path traversal; CVE-2026-48324 CVSS 9.1 SQL injection to RCE; CVE-2026-48327 CVSS 9.0 incorrect authorization) remediated in ColdFusion 2025 Update 11 and 2023 Update 22; APSB26-73 for Adobe Commerce/Magento Open Source, patching CVE-2026-48358 (NVD-rated CVSS 10.0, unauthenticated zero-interaction improper output escaping in the webhooks component leading to arbitrary code execution) and CVE-2026-48356 (CVSS 9.6, arbitrary file upload to privilege escalation), affecting every supported 2.4.x line; and APSB26-74 for Adobe Experience Manager, patching CVE-2026-48259 (CVSS 9.6 SSRF to RCE) and CVE-2026-48359 (CVSS 9.6 XXE to RCE), both credited to Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote. Finally, Broadcom published VMSA-2026-0005 for VMware Avi Load Balancer, addressing seven vulnerabilities (CVE-2026-47865 through CVE-2026-47871) spanning authentication bypass, remote code execution, privilege escalation, and directory traversal; the headline flaw, CVE-2026-47865 (CVSS 9.8), allows a network-positioned attacker with no credentials to bypass authentication and reach the Avi control plane, and was discovered by Filip Waeytens of NATO's technology and cyber hub. None of the 17 CVEs tracked in this roundup carries a confirmed in-the-wild exploitation report or CISA KEV listing at time of writing; the hunt rationale qualifies the cluster purely on CVSS/network-vector severity and the compressed multi-vendor patch timing that raises near-term weaponization risk, particularly for the unauthenticated ColdFusion, Commerce webhooks, and Avi Load Balancer flaws.
Weaknesses (CWE)
CWE-822, CWE-284, CWE-416, CWE-22, CWE-94, CWE-20, CWE-863, CWE-306, CWE-89, CWE-434
Target sectors: technology, finance, government administration, retail, ecommerce, health, critical infrastructure
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15718, CVE-2026-15719, CVE-2026-15764, CVE-2026-15765, CVE-2026-48318, CVE-2026-48322, CVE-2026-48284, CVE-2026-48321, CVE-2026-48325, CVE-2026-48319, T1190, T1189, T1078, T1203, T1059, T1505, T1068, T1548, T1211, T1070