CISA’s addition of four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue shows how quickly attackers are weaponizing flaws across enterprise applications, CMS platforms, and AI orchestration tools.
The listed vulnerabilities affect Adobe ColdFusion, JoomShaper SP Page Builder, Joomlack Page Builder, and Langflow. The most serious issues can allow remote code execution through path traversal, arbitrary file upload, or weak access controls.
The Adobe ColdFusion flaw is especially urgent because exploitation was reportedly observed within hours of public disclosure. ColdFusion servers often sit behind business applications and may have access to databases, file stores, credentials, and internal systems.
The Joomla plugin vulnerabilities are also serious because attackers can upload PHP web shells and create administrative access on vulnerable websites. Once a web shell is planted, patching the plugin alone may not remove the attacker’s access.
The Langflow issue shows the growing risk around AI platforms. Attackers abused weak authorization controls to access other users’ flows and steal sensitive keys, including LLM provider credentials and cloud secrets.
Organizations should apply the required fixes immediately, review exposed servers and websites, and investigate for signs of prior compromise. Security teams should look for unexpected PHP files, web shells, suspicious uploads, unusual flow execution, new administrator accounts, outbound connections, and exposed API keys.
The key lesson is that once a vulnerability enters CISA’s exploited list, it has moved from theoretical risk to active attacker playbook. Waiting for the next maintenance window is less patch management and more an optimistic donation to the internet’s criminal ecosystem.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the
Source: CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV via The Hacker News — published 08 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.