< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-08T11:03:12+05:30

CISA Updates KEV Catalog with Four Actively Exploited Adobe, Joomla, and Langflow Vulnerabilities

CISA added four actively exploited vulnerabilities in Adobe, Joomla, and Langflow to its KEV catalog, with CVSS scores up to 10.0, urging FCEB agencies to patch by July 10, 2026. The flaws enable remote code execution, web shell deployment, and credential theft, with exploitation observed in real-world attacks targeting multiple platforms.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities are listed below -

CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the

Read original article

*** END OF TRANSMISSION ***