The U.S. Cybersecurity and Infrastructure Security Agency has added four critical vulnerabilities affecting Adobe ColdFusion, Langflow, and Joomla extensions to its Known Exploited Vulnerabilities catalog following active exploitation.
Key Points
- CISA added CVE-2026-48282, CVE-2026-56290, CVE-2026-55255, and CVE-2026-48908 to its KEV catalog due to confirmed real-world attacks.
- Adobe ColdFusion (CVE-2026-48282) and JoomShaper SP Page Builder (CVE-2026-48908) both carry maximum CVSS scores of 10.0.
- Attackers are using CVE-2026-55255 in Langflow to steal sensitive AWS and LLM provider keys through cross-tenant IDOR exploits.
- Exploitation of Joomlack Page Builder (CVE-2026-56290) involves deploying web shells, with patches available in version 3.6.0.
- Federal Civilian Executive Branch agencies must apply all necessary security updates by the July 10, 2026, deadline to mitigate these risks.
Why it Matters
- These vulnerabilities represent a significant threat to enterprise infrastructure, as attackers are actively using them to gain unauthorized access, deploy web shells, and steal cloud credentials. Organizations must prioritize patching these specific flaws to prevent data breaches and the potential deployment of botnets or ransomware.