Post
CRITICAL

CISA Adds 4 Actively Exploited Flaws to KEV, Including Adobe ColdFusion and Langflow

· cve · vulnerability · rce · llm

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, citing evidence of in-the-wild exploitation. The list includes CVE-2026-48282, a CVSS 10.0 path traversal flaw in Adobe ColdFusion that enables arbitrary code execution, alongside flaws in Joomla and the Langflow AI workflow platform. Federal agencies have been ordered to patch the ColdFusion flaw by Friday. Langflow’s inclusion extends the exploited-vulnerability list into AI application tooling. Organizations running any of the four affected products should prioritize patching immediately.