AI Stories on SHORT INFO are generated & curated with AI
unverified 11 Jul, 11:10

CISA adds four actively exploited zero-days to KEV catalog including Adobe ColdFusion Langflow Joomla builders

Any organization running Adobe $ADBE ColdFusion should patch now. CISA added four actively exploited vulnerabilities to its catalog this week, including flaws in ColdFusion, Langflow, and two Joomla page builders. US federal agencies were ordered to fix them by July 10.

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and the risk is not limited to the federal agencies ordered to patch them. The flaws affect widely deployed software: a path traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) that can lead to arbitrary code execution, an authorization bypass in Langflow (CVE-2026-55255), and two Joomla page builder vulnerabilities (CVE-2026-56290 and CVE-2026-48908) that let unauthenticated attackers upload malicious files. One of the Joomla flaws was exploited as a zero-day before a patch existed. CISA set a July 10 deadline for federal civilian agencies, but any internet-facing installation of the affected products is a target. Organizations running these tools should apply vendor updates and check for signs of compromise. Source: CISA / The Hacker News (https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html)

Published on
BlueskyXRedditFacebookThreads