Cybersecurity Headlines — July 09, 2026


From the Trenches

CISA didn’t mince words today — ColdFusion, Langflow, and Joomla all landing on the KEV catalog at once, with an explicit order to federal agencies to prioritize the Langflow auth bypass specifically. That Langflow flaw (CVE-2026-55255) has now shown up in three different contexts this week: agentic ransomware delivery, credential harvesting, and now a federal patching mandate. If it’s in your environment, it’s earned the top of your queue.

The Ubiquiti UniFi story is a reminder that “critical infrastructure” isn’t only enterprise data centers — UniFi gear runs a huge share of SMB and home-office networking, and a max-severity flaw spanning Connect, Talk, Access, Protect, and OS is about as broad a blast radius as one vendor patch cycle gets.

The US-China mutual AI warnings around Claude Code are worth watching as a geopolitical signal more than a technical one for now — allegations on both sides, no independently verified technical findings yet as of this write-up. Worth following as it develops rather than treating either claim as settled.

🔧 Patch Priority: Langflow (CVE-2026-55255) — CISA-mandated priority patch, actively exploited for both credential harvesting and ransomware delivery this week.


Compiled daily. Stay patched, stay vigilant.