**Urgent: Four Critical Vulnerabilities Added to CISA KEV Catalog After Active Exploitation**
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, adding four critical security flaws that have already been observed in the wild. These vulnerabilities span across popular content management systems and AI workflow platforms, with some being actively exploited within hours of disclosure.
The newly cataloged vulnerabilities include:
**1. CVE-2026-48282 (CVSS: 10.0)** – A path traversal vulnerability in Adobe ColdFusion allowing arbitrary code execution.
**2. CVE-2026-56290 (CVSS: 10.0)** – An improper access control flaw in Joomlack Page Builder enabling remote code execution via unauthenticated file upload.
**3. CVE-2026-55255 (CVSS: 6.1)** – An authorization bypass via user-controlled key in Langflow, permitting cross-tenant data access and RCE opportunities.
**4. CVE-2026-48908 (CVSS: 10.0)** – An unrestricted dangerous file upload vulnerability in JoomShaper SP Page Builder, leading to PHP code execution.
**Rapid Exploitation Observed**
According to KEVIntel researcher Ryan Dewhurst, exploitation of CVE-2026-48282 was detected just hours after public disclosure, with traffic traced to an IP address in India. Similarly, CVE-2026-48908 has been weaponized as a zero-day to plant web shells via HTTP POST requests, resulting in unauthorized Super User account creation.
The Joomla and WordPress site security service mySites.guru reported ongoing exploitation attempts targeting CVE-2026-56290, with attackers deploying web shells specifically in `/media/com_pagebuilderck/` directories.
**AI Platform Under Siege**
Sysdig revealed that CVE-2026-55255 has been exploited as part of a sustained campaign (June 22β25, 2026) alongside another Langflow RCE flaw (CVE-2026-33017). The attack chain involves reconnaissance, IDOR exploitation, and deployment of payloads linked to botnet and cryptojacking operationsβdubbed **JADEPUFFER**βcapable of stealing cloud credentials and LLM API keys.
Given the active exploitation, CISA and Sysdig strongly urge organizationsβespecially Federal Civilian Executive Branch agenciesβto apply vendor patches immediately, with a compliance deadline set for **July 10, 2026**.
—
**Original Source:**
Ravie Lakshmanan. βCISA Adds 4 Security Flaws to Known Exploited Vulnerabilities Catalog After Evidence of Active Exploitation.β *The Hacker News*, 8 July 2026. [https://thehackernews.com/2026/07/cisa-adds-four-security-flaws-to-its.html](https://thehackernews.com/2026/07/cisa-adds-four-security-flaws-to-its.html)



