< Back to all clusters
[TECHNOLOGY] · Germany, United States · 5 sources

US CISA and German BSI order urgent patches for critical software flaws

Germany’s Federal Office for Information Security (BSI) issued a warning on July 9 about multiple high‑severity vulnerabilities in the Linux kernel, assigning a combined CVSS score of 8.6. The flaws could allow remote attackers to launch denial‑of‑service attacks and other unspecified exploits across many Linux distributions, including those from SUSE, IBM, Red Hat and Oracle. Oracle responded with Security Advisory ELSA‑2026‑50372, releasing an important update for its Unbreakable Enterprise Kernel to remediate the listed CVEs.

In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) added four new critical vulnerabilities to its catalog, demanding that federal agencies patch them by July 10. The most serious is CVE‑2026‑48282, a path‑traversal flaw in Adobe ColdFusion rated CVSS 10.0, already exploited within hours of disclosure. Other entries include a CVE‑2026‑55255 flaw in the AI framework Langflow (CVSS 9.9), a “GhostLock” Linux‑kernel privilege‑escalation bug (CVE‑2026‑43499) that can achieve root access in seconds, and high‑severity issues in UniFi Connect and Microsoft SharePoint. The advisories stress rapid mitigation to prevent widespread exploitation.