CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday. All four are being actively exploited right now. Federal agencies have until July 10 to patch.
Here’s the list:
CVE-2026-48282 (CVSS 10.0) — Path traversal in Adobe ColdFusion. Lets attackers execute arbitrary code. Exploitation was detected within hours of Adobe’s disclosure. An attempt was traced to an IP in India.
CVE-2026-56290 (CVSS 10.0) — Improper access control in Joomlack Page Builder. Unauthenticated file upload leads to remote code execution. Web shells have been spotted on compromised sites since June 27. Fixed in Page Builder CK 3.6.0. If you find a stray PHP file under /media/com_pagebuilderck/, that’s your red flag.
CVE-2026-48908 (CVSS 10.0) — Unrestricted file upload in JoomShaper SP Page Builder. Also allows unauthenticated PHP upload and execution. Attackers have used it to create Super User accounts. Update to SP Page Builder 6.6.2 or later.
CVE-2026-55255 (CVSS 6.1) — Authorization bypass in Langflow. An authenticated attacker can execute any flow belonging to another user by guessing their flow ID. Sysdig documented a sustained campaign between June 22-25 using this bug alongside an unauthenticated RCE (CVE-2026-33017) to steal LLM provider keys and AWS credentials. The activity looks opportunistic and financially motivated — likely botnet or cryptojacking operations.
The Langflow ecosystem has been hit hard. This is the latest in a string of exploited Langflow flaws including CVE-2025-3248, CVE-2026-0770, CVE-2026-33017, and others. Last week, Sysdig also documented the first known case of agentic ransomware (“JADEPUFFER”) using a Langflow exploit end-to-end.
