CISA Adds 4 Critical Exploited Flaws to KEV: Adobe, Joomla, Langflow (2026)

In a recent development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the urgent need for attention and action. These flaws, discovered in Adobe, Joomla, and Langflow, have already been actively exploited, posing significant risks to the security of digital systems and networks.

The Vulnerabilities and Their Impact

The first vulnerability, CVE-2026-48282, is a path traversal issue in Adobe ColdFusion, allowing for arbitrary code execution. This is a severe flaw as it can be exploited to gain control of systems, potentially leading to data breaches or further system compromise. The second vulnerability, CVE-2026-56290, is an improper access control issue in Joomlack Page Builder, enabling remote code execution through unauthenticated file uploads. This vulnerability can be exploited to inject malicious code into websites, compromising their integrity and potentially exposing user data.

The third vulnerability, CVE-2026-55255, is an authorization bypass issue in Langflow, allowing authenticated attackers to execute flows belonging to other users. This vulnerability could lead to the unauthorized access and manipulation of sensitive data, as well as the potential for further system exploitation. The fourth vulnerability, CVE-2026-48908, is an unrestricted file upload issue in JoomShaper SP Page Builder, allowing unauthenticated users to upload and execute PHP code. This vulnerability can be exploited to gain remote control over systems, potentially leading to a full system compromise.

Active Exploitation and Implications

What makes these vulnerabilities particularly concerning is the evidence of active exploitation. CVE-2026-48282 was exploited within hours of its public disclosure, with attempts originating from India. CVE-2026-48908 was also exploited as a zero-day, with attackers using an HTTP POST request to upload a PHP file. This highlights the urgency and sophistication of the threat actors involved.

The Joomla and WordPress site manager service has also recorded exploitation attempts aimed at CVE-2026-56290, with the goal of delivering a web shell on susceptible sites. This vulnerability has been addressed in Page Builder CK version 3.6.0, but the potential for further exploitation remains a concern.

CVE-2026-55255 has been observed in a sustained campaign by a lone operator, who exploited it alongside another Langflow vulnerability, CVE-2026-33017. This campaign targeted AI orchestration platforms, aiming to steal large language model (LLM) provider keys and AWS keys. The motivation behind this attack is assessed to be financial, with the potential for significant impact on the targeted organizations.

Langflow Flaws and the Rise of Agentic Ransomware

The Langflow vulnerabilities, including CVE-2026-55255, are part of a growing trend of bad actors targeting AI-related platforms. Langflow has been a frequent target over the past year, with multiple vulnerabilities exploited. Last week, Sysdig documented the first known case of agentic ransomware, codenamed JADEPUFFER, where a human operator deployed an artificial agent to handle the entire extortion operation by exploiting a Langflow flaw. This development highlights the evolving nature of cyber threats and the potential for AI-powered attacks.

Conclusion: The Need for Swift Action

The addition of these vulnerabilities to the KEV catalog serves as a stark reminder of the ever-present threat landscape. With active exploitation already underway, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary fixes by July 10, 2026. The urgency of this situation cannot be overstated, as these vulnerabilities pose a significant risk to the security and integrity of digital systems.

As we navigate the complex world of cybersecurity, it is crucial to remain vigilant and proactive. The exploitation of these vulnerabilities underscores the importance of timely patch management and the need for organizations to prioritize security measures. In my opinion, this incident serves as a wake-up call, emphasizing the ongoing battle against cyber threats and the critical role of cybersecurity agencies in safeguarding our digital infrastructure.

CISA Adds 4 Critical Exploited Flaws to KEV: Adobe, Joomla, Langflow (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Catherine Tremblay

Last Updated:

Views: 5964

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.