logo

U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog

ID: 2d8a89e0-1a90-5276-a8d1-9b8e0a423b47

STIX ID: report--2d8a89e0-1a90-5276-a8d1-9b8e0a423b47

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

CISA added several critical flaws—including an Adobe ColdFusion path traversal (CVE-2026-48282), JoomShaper and Joomlack page builder upload/ACL bypasses (CVE-2026-48908, CVE-2026-56290), and a Langflow authorization bypass (CVE-2026-55255)—to its Known Exploited Vulnerabilities catalog after multiple reports of active exploitation, rapid weaponization (including web shells and remote code execution), credential theft, and observed attack infrastructure; agencies and site owners are urged to patch immediately and search for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.