LIVE · cybersecurity feed
Live wire
CVE-2026-48282high

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

zeroday.news · 24d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). These newly identified weaknesses, which affect products from Adobe, Joomla, and Langflow, are reportedly being actively exploited in the wild.

The inclusion of these vulnerabilities in the KEV catalog mandates that federal agencies implement specific security measures to protect their networks. While CISA's directive specifically targets federal civilian executive branch agencies, it serves as a critical alert for all organizations to prioritize patching these flaws.

Among the newly added vulnerabilities is a flaw in Adobe Commerce. This issue, identified by CISA, is a critical security gap that could allow for unauthorized access or malicious code execution within affected Adobe Commerce instances.

Additionally, two vulnerabilities affecting Joomla, a popular content management system, have been added to the KEV catalog. These flaws, if exploited, could potentially compromise Joomla websites, leading to data breaches or defacement.

The fourth vulnerability concerns Langflow, an open-source framework for developing and orchestrating large language model applications. This addition highlights the growing cybersecurity concerns surrounding AI development tools, as vulnerabilities in such platforms could have significant implications for the security of AI-powered systems.

CISA has not provided specific details regarding the nature of the exploits or the actors behind them for these four vulnerabilities. However, the agency's inclusion in the KEV catalog signifies a high level of confidence that these flaws are being actively targeted by malicious actors.

Organizations using Adobe Commerce, Joomla, or Langflow are strongly advised to review their systems for these vulnerabilities and apply any available patches or mitigation strategies as soon as possible. Staying informed about and addressing vulnerabilities listed in the KEV catalog is a crucial step in maintaining a robust cybersecurity posture.

This action by CISA underscores the dynamic nature of the threat landscape and the importance of continuous vulnerability management and timely patching to defend against active exploitation.

cisavulnerabilitykevadobejoomla
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]