1. Top Action Item

Move funds off any Coldcard hardware wallet whose seed was generated on affected firmware (post-March 2021), update the firmware, and generate a fresh wallet — a Coldcard flaw is linked to a July 30 heist that drained 1,082.65 BTC (~$70.2 million) in 41 minutes. Enterprise teams: patch Adobe Campaign Classic (CVE-2026-48449, CVSS 10.0) immediately — it allows arbitrary code execution with no user interaction. Everyone else: update Google Chrome to 151; the last three Chrome releases fixed 1,442 vulnerabilities.


2. Exploited This Week

Coldcard hardware wallet firmware flaw (no CVE published)

Adform ad-script supply-chain compromise (no CVE)


3. Critical Patch Roundup

Adobe Campaign Classic — CVE-2026-48449

Google Chrome 149–151 — 1,442 vulnerabilities fixed

Microsoft Edge (Chromium) — CVE-2026-13028, CVE-2026-13030, CVE-2026-13032, CVE-2026-13037

Microsoft Windows, Office, and Azure — advisory updates this week

4G and 5G core networks — 84 flaws including session hijacking (no CVEs published)


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Coldcard hardware wallet — patched firmware (no CVE) — exploited: $70M Bitcoin theft; migrate funds after updating.
  2. Adobe Campaign Classic — CVE-2026-48449 — critical (CVSS 10.0), RCE without user interaction.
  3. Google Chrome 151 / Microsoft Edge latest — 370 fixes, 1,442 across Chrome 149–151 incl. CVE-2026-13028/13030/13032/13037 — widely deployed browsers.
  4. Windows DHCP Client — CVE-2026-54128 — RCE (see MSRC for patch).
  5. Microsoft Office — CVE-2026-55129 — RCE (see MSRC for patch).
  6. Windows Admin Center — CVE-2026-56197 — RCE (see MSRC for patch).
  7. Azure Cosmos DB — CVE-2026-66803 — RCE via improper access control (see MSRC for patch).
  8. 4G/5G core network vendor updates — 84 flaws incl. session hijacking — contact vendors.

Sources