HomeSecurityCISA KEV: 4 Adobe, Joomla and Langflow vulnerabilities

CISA KEV: 4 vulnerabilities in Adobe, Joomla and Langflow

The Cybersecurity and Infrastructure Security Agency ( CISA ) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) list , confirming that they are actively being exploited online. The vulnerabilities affect Adobe , Joomla , and Langflow products , and their severity ranges from moderate to critical — with three of them carrying a CVSS score of 10.0 , the maximum risk rating. Organizations using affected systems are urged to apply the available security updates immediately.

See also: CISA adds Joomla JCE vulnerability to KEV List

CISA KEV vulnerability list Adobe ColdFusion Joomla Langflow

CISA KEV: The four new vulnerabilities that are being actively exploited

The first vulnerability, CVE-2026-48282 (CVSS 10.0), concerns Adobe ColdFusion and is a path traversal that could lead to arbitrary code execution in the context of the current user. Its exploitation was observed within hours of the public disclosure, with security researcher Ryan Dewhurst reporting an attempt from an IP address geographically located in India (103.207.14[.]220). This highlights how quickly malicious actors are exploiting new vulnerability disclosures.

The second vulnerability, CVE-2026-56290 (CVSS 10.0), is located in Joomla PageBuilder CK and concerns improper access control that allows remote code execution via unauthorized file uploads. Joomla and WordPress have recorded attempts to exploit it since June 27, 2026, aiming to install a web shell on vulnerable sites. The first confirmed web shell was found in the path /media/com_pagebuilderck/gfonts/bhup.php, an uploader shell based on the $_POST['_upl']. The issue has been addressed in PageBuilder CK version 3.6.0.

The third vulnerability, CVE-2026-48908 (CVSS 10.0), also affects JoomShaper SP Page Builder and allows unauthorized users to upload arbitrary files, ultimately leading to PHP code execution . This vulnerability was exploited as a zero-day via an HTTP POST request to the endpoint index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon , followed by the creation of a new Super User account. SP Page Builder users are advised to upgrade to version 6.6.2 or later as soon as possible.

CISA KEV and Langflow: AI and AWS key theft

The fourth vulnerability, CVE-2026-55255 (CVSS 6.1), affects Langflow — a popular AI orchestration platform — and is a case of cross-tenant insecure direct object reference (IDOR). Specifically, it allows an authorized attacker to execute any flow owned by another user, simply by specifying the victim’s flow ID in the request. Sysdig revealed that it observed a lone threat actor (45,207,216[.]55) exploiting this vulnerability along with CVE-2026-33017 — an unauthenticated remote code execution in Langflow — as part of a coordinated campaign that lasted from June 22 to 25, 2026.

See also: CISA adds 6 new Fortinet, Microsoft and Adobe vulnerabilities

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 1

The activity is assessed as opportunistic and financially motivated. The attacker used RCE to target the host, while IDOR was used to steal LLM (Large Language Model) and AWS from other platform tenants. As Sysdig: “AI orchestration platforms are credential vaults in their own right, and this actor was well aware of this.” The attack chain involves deploying payloads that download a second-stage downloader, compatible with botnet and cryptojacking, while the exact nature of the final payload remains unknown.

It is worth noting that Langflow has been repeatedly targeted by malicious actors over the past year. The list of exploited vulnerabilities includes CVE-2025-3248, CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, CVE-2025-34291 , and CVE-2026-5027. This pattern suggests that AI orchestration platforms are becoming an increasingly attractive target for attackers seeking access to valuable credentials and infrastructure.

In a related development, Sysdig recently documented the first known case of agentic ransomware, in which a human operator deployed an artificial agent and provided the necessary infrastructure for the agent to manage the entire extortion operation from start to finish — a worrying development in the cyberthreat landscape.

CISA KEV: Practical recommendations for protection

For site administrators using Joomla or WordPress with the affected plugins, mySites.guru recommends looking for suspicious PHP files under the /media/com_pagebuilderck/ , /images , /media , /templates , and /administrator directories. Since the vulnerability allows an attacker to choose the target folder, malicious files could be located anywhere in the file system — not just in the obvious upload directories. For Adobe ColdFusion users , immediate patching is imperative, given the speed with which the vulnerability was exploited after it was disclosed.

See also: Adobe: Urgent security updates for ColdFusion and Campaign Classic

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 1

CISA requires U.S. federal agencies to address vulnerabilities on the KEV list within specified deadlines, but the recommendations apply to every organization worldwide. Active exploitation of all four vulnerabilities confirms that attackers are closely monitoring new disclosures and acting promptly. Rapidly implementing security updates, monitoring logs for suspicious activity, and using intrusion detection tools are key defenses for any organization using affected products.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS