Post
CRITICAL

CISA Adds 4 Actively Exploited Flaws to KEV: ColdFusion, Langflow, Joomla

· cve · vulnerability · zero-day

CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-48282 (CVSS 10.0), a path traversal bug in Adobe ColdFusion that can lead to arbitrary code execution; an auth bypass in Langflow, the visual framework for building AI agents; and two Joomla extension flaws. Federal agencies have until July 10 to patch. Organizations running ColdFusion or Langflow should prioritize patching immediately given confirmed in-the-wild exploitation.