ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15719
+1 in the same advisory: …15718
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

NVD description · AI analysis pending
5.4
group max
<1%
  • mozilla firefox
CVE-2026-15764
+1 in the same advisory: …15765
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to po

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

NVD description · AI analysis pending
7.5<1%
  • google chrome
CVE-2026-47865
VMware Avi Load Balancer contains an authentication bypass vulnerability.

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)

NVD description · AI analysis pending
9.8<1%
  • broadcom vmware avi load balancer
CVE-2026-48359
+1 in the same advisory: …48259
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execu

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

NVD description · AI analysis pending
9.61%
  • adobe experience manager
CVE-2026-48322
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the contex

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

NVD description · AI analysis pending
9.9
group max
1%
  • adobe coldfusion
CVE-2026-48356
+1 in the same advisory: …48358
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of t

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

NVD description · AI analysis pending
9.3
group max
1%
  • adobe commerce
  • adobe commerce b2b
  • adobe magento
  • +1 more
Full article614 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 15, 2026Vulnerability / Browser Security

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.

The vulnerabilities are listed below -

  • CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component
  • CVE-2026-15719, a site isolation in the DOM: Navigation component

"We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw," Mozilla said in an advisory. Both vulnerabilities have been addressed in Firefox version 152.0.6.

The release comes as Google shipped fixes for 15 security flaws, including two critical use-after-free bugs in Ozone (CVE-2026-15764 and CVE-2026-15765), a cross-platform abstraction layer that allows the browser to interact natively with various display servers and windowing systems. It supports Linux, ChromeOS, and Fuchsia.

"Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page," according to a description of CVE-2026-15764 in the NIST National Vulnerability Database (NVD).

The shortcomings have been patched in Chrome version 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux.

In a related development, Adobe has published security updates for 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Of these, eight impact Adobe ColdFusion -

  • CVE-2026-48318 (CVSS score: 9.9) - A path traversal vulnerability that could lead to arbitrary code execution
  • CVE-2026-48322 (CVSS score: 9.6) - A code injection vulnerability that could lead to arbitrary code execution
  • CVE-2026-48284 (CVSS score: 9.6) - An improper input validation vulnerability that could lead to arbitrary code execution
  • CVE-2026-48321 (CVSS score: 9.3) - An incorrect authorization vulnerability that could lead to privilege escalation
  • CVE-2026-48325 (CVSS score: 9.3) - A missing authentication for a critical function vulnerability that could lead to arbitrary code execution
  • CVE-2026-48319 (CVSS score: 9.1) - A path traversal vulnerability that could lead to arbitrary code execution
  • CVE-2026-48324 (CVSS score: 9.1) - An SQL injection vulnerability that could lead to arbitrary code execution
  • CVE-2026-48327 (CVSS score: 9.0) - An incorrect authorization vulnerability that could lead to arbitrary code execution

The CodeFusion flaws have been remediated in versions ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22. Also fixed by Adobe are two critical flaws each in Adobe Commerce and Magento Open Source and Adobe Experience Manager -

  • CVE-2026-48356 (CVSS score: 9.6) - A file upload vulnerability in Adobe Commerce and Magento Open Source that could lead to privilege escalation
  • CVE-2026-48358 (CVSS score: 9.1) - An improper encoding or escaping of output vulnerability in Adobe Commerce and Magento Open Source that could lead to arbitrary code execution
  • CVE-2026-48259 (CVSS score: 9.6) - A server-side request forgery vulnerability in Adobe Experience Manager that could lead to arbitrary code execution
  • CVE-2026-48359 (CVSS score: 9.6) - An improper restriction of XML external entity reference vulnerability in Adobe Experience Manager that could lead to arbitrary code execution

Elsewhere, Broadcom has released a fix for a critical authentication bypass vulnerability in VMware Avi Load Balancer (CVE-2026-47865, CVSS score: 9.8) that a malicious user with network access can exploit to access the Avi Control plane. Filip Waeytens of the NATO Cyber Security Centre (NCSC) has been credited with discovering and reporting the flaw.

Although none of the vulnerabilities have been marked as actively exploited, it's essential that organizations install the latest updates, given that threat actors are known to weaponize flaws in these products in attacks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html