The U.S. Cybersecurity and Infrastructure Security Agency has added four security flaws to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. These vulnerabilities are found in Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder, and they could lead to arbitrary code execution, remote code execution, and unauthorized access. The most severe vulnerabilities are CVE-2026-48282 and CVE-2026-56290, with CVSS scores of 10.0, indicating a critical severity level.
The exploitation of these vulnerabilities can occur through various attack vectors, including path traversal, improper access control, and authorization bypass. In the case of CVE-2026-48282, an attacker could exploit the vulnerability to execute arbitrary code in the context of the current user. For CVE-2026-56290, an attacker could upload arbitrary files, leading to remote code execution. The vulnerabilities in Langflow, including CVE-2026-55255, can be exploited to bypass authorization and execute flows belonging to other users. These vulnerabilities can be exploited using various techniques, including phishing, social engineering, and exploitation of known vulnerabilities.
The active exploitation of these vulnerabilities has significant strategic implications, as it could lead to the compromise of sensitive information, disruption of critical services, and financial losses. The fact that these vulnerabilities are being actively exploited in the wild underscores the importance of applying patches and updates in a timely manner. Users of the affected products are advised to update to the latest versions, such as Adobe ColdFusion 2023, Joomlack Page Builder 3.6.0, and JoomShaper SP Page Builder 6.6.2, to safeguard their networks and prevent potential attacks. The exploitation of these vulnerabilities is assessed to be opportunistic and financially motivated, and it is essential for organizations to take proactive measures to protect themselves from these threats.
Severity:
High
Attack Surface:
Web Application, Content Management System
Tactics:
Initial Access, Execution, Privilege Escalation, Persistence
Techniques:
T1190 – Exploitation for Client Execution
T1204 – User Execution
References:
1. https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog
3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
5. https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
SuperPRO’s Threat Countermeasures Procedures:
1. Update Adobe ColdFusion to the latest version
2. Upgrade Joomlack Page Builder to version 3.6.0 or later
3. Update JoomShaper SP Page Builder to version 6.6.2 or later
4. Apply the patch for CVE-2026-55255 in Langflow
5. Disable unnecessary features and plugins in Adobe ColdFusion and Joomla
6. Monitor for suspicious activity and unauthorized access attempts
Contributed by: Syafiq