{"id":1647,"date":"2026-07-08T08:02:11","date_gmt":"2026-07-08T08:02:11","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1647"},"modified":"2026-07-08T08:02:11","modified_gmt":"2026-07-08T08:02:11","slug":"cisa-adds-4-actively-exploited-adobe-joomla-and-langflow-flaws-to-kev","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1647","title":{"rendered":"CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 08, 2026<\/span><\/span><span class=\"p-tags\">AI Security \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgZn36WwWfaOwK7XCU9aKjVPS7QAyrnBKsKMXtVRyYbD2X30HI-ojl5F8ttD9VcbXB36anuKWq-JGEhzPq1fjwnEhKPKMjkPDMPAFe8OqR85N1dc0QZoZ7JCN9ziqGuQ8M4irelfxa_zca62EV-s9qBO9WI47ECtzM8Zi2X8T-MFfuRRbJQ8u48Y2RRt3UT\/s1700-e365\/cisa-main.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/07\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">added<\/a> <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/07\/cisa-adds-three-known-exploited-vulnerabilities-catalog\" target=\"_blank\">four security flaws<\/a> to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, citing evidence of active exploitation.<\/p>\n<p>The vulnerabilities are listed below &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48282\" target=\"_blank\">CVE-2026-48282<\/a><\/strong> (CVSS score: 10.0) &#8211; A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user.<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-56290\" target=\"_blank\">CVE-2026-56290<\/a><\/strong> (CVSS score: 10.0) &#8211;  An improper access control vulnerability in  Joomlack Page Builder that could allow for remote code execution via unauthenticated arbitrary file upload.<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-55255\" target=\"_blank\">CVE-2026-55255<\/a><\/strong> (CVSS score: 6.1) &#8211; An authorization bypass through a user-controlled key vulnerability in  Langflow that could allow an authenticated attacker to execute any flow belonging to another user by specifying the victim&#8217;s flow ID in the request.<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48908\" target=\"_blank\">CVE-2026-48908<\/a><\/strong> (CVSS score: 10.0) &#8211; An unrestricted upload of a file with a dangerous type vulnerability in JoomShaper SP Page Builder that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.<\/li>\n<\/ul>\n<p>It&#8217;s worth noting that <a href=\"https:\/\/www.resecurity.com\/blog\/article\/cve-2026-48282-adobe-coldfusion-rds-path-traversal-leading-to-rce\" target=\"_blank\">exploitation<\/a> of CVE-2026-48282 was observed within hours of public disclosure, with Ryan Dewhurst, security researcher and founder of KEVIntel, telling The Hacker News that an attempt was recorded from an IP address geolocated to India (\u00ab103.207.14[.]220\u00bb).<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>CVE-2026-48908, on the other hand, is said to have been exploited as a zero-day to upload a PHP file by means of an HTTP POST request to the \u00abindex.php?option=com_sppagebuilder&amp;task=asset.uploadCustomIcon\u00bb endpoint, followed by the appearance of a new Super User account, per <a href=\"https:\/\/mysites.guru\/blog\/sp-page-builder-zero-day-uploadcustomicon-rce\/\" target=\"_blank\">mySites.guru<\/a>. Users of SP Page Builder are advised to update to version 6.6.2 or later.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The Joomla and WordPress site manager service has also recorded exploitation efforts aimed at CVE-2026-56290 as of June 27, 2026, to deliver a web shell on susceptible sites. The issue has been addressed in Page Builder CK version 3.6.0.<\/p>\n<p>\u00abThe first confirmed web shell we caught sat at \/media\/com_pagebuilderck\/gfonts\/bhup.php, an uploader shell keyed on a $_POST[&#8216;_upl&#8217;] field,\u00bb mySites.guru <a href=\"https:\/\/mysites.guru\/blog\/pagebuilderck-unauthenticated-file-upload-rce\/\" target=\"_blank\">explained<\/a>.<\/p>\n<p>\u00abBecause the flaw lets the attacker pick the destination folder, a planted file could be anywhere, not just the obvious upload directories, so look for stray PHP files under \/media\/com_pagebuilderck\/ first and then more widely under \/images, \/media, \/templates, and \/administrator.\u00bb<\/p>\n<p>As for CVE-2026-55255, Sysdig <a href=\"https:\/\/www.sysdig.com\/blog\/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited\" target=\"_blank\">revealed<\/a> late last month that it observed a lone operator (\u00ab45.207.216[.]55\u00bb) weaponizing the vulnerability along with CVE-2026-33017, an unauthenticated remote code execution flaw in Langflow, as part of a sustained campaign that lasted between June 22 and June 25, 2026.<\/p>\n<p>\u00abOn June 25, 2026, the operator (45.207.216[.]55) returned to an internet-exposed Langflow instance they had first probed three days before and ran a tight, methodical session: application\/auth reconnaissance \u2192 flow enumeration \u2192 the CVE-2026-55255 IDOR \u2192 a sustained loop of the CVE-2026-33017 RCE with outbound connection attempts,\u00bb Sysdig&#8217;s Michael Clark said.<\/p>\n<p>The activity is assessed to be opportunistic and financially motivated. The exploitation of CVE-2026-33017 is followed by the deployment of payloads designed to fetch a second-stage downloader responsible for delivering additional malware. This attack chain is consistent with botnet and cryptojacking attacks. That said, the exact nature of the final payload is unknown.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The cloud security company has described CVE-2026-55255 as a case of cross-tenant insecure direct object reference (IDOR), which the threat actor exploited to steal large language model (LLM) provider keys and AWS keys.<\/p>\n<p>\u00abAI orchestration platforms are a trove of credentials in their own right, and this operator clearly knew it,\u00bb Sysdig said. \u00abThe RCE went after the host, while the IDOR went after other tenants&#8217; flows and their keys.\u00bb<\/p>\n<p>The development makes it the latest Langflow flaw to be exploited by bad actors over the past year after CVE-2025-3248, CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, CVE-2025-34291, and CVE-2026-5027.<\/p>\n<p>Last week, Sysdig also documented the first known case of agentic ransomware in which a human operator deployed an artificial agent and provisioned the necessary infrastructure to let the agent handle the entire extortion operation from start to finish by exploiting the CVE-2025-3248 Langflow flaw. It has been codenamed <strong>JADEPUFFER<\/strong>.<\/p>\n<p>In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the fixes by July 10, 2026, to safeguard their networks.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 08, 2026AI Security \/ Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1648,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[201,200,1135,62,128,11,2072,203,796],"class_list":["post-1647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actively","tag-adds","tag-adobe","tag-cisa","tag-exploited","tag-flaws","tag-joomla","tag-kev","tag-langflow"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1647"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1647\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1648"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}