logo

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

ID: 9efa8bcb-acd7-5c1a-9808-3204662fab8c

STIX ID: report--9efa8bcb-acd7-5c1a-9808-3204662fab8c

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

CISA added four actively exploited vulnerabilities—including multiple CVSS 10.0 flaws—in Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder; attackers have used these flaws to upload web shells, create unauthorized accounts, steal LLM and AWS keys via an IDOR, and deploy payloads consistent with botnet/cryptojacking and agentic ransomware (JADEPUFFER), prompting urgent patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.