CISA has incorporated four new vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. These flaws, affecting products from Adobe, Joomla, and Langflow, are all currently under active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). These newly identified weaknesses, which affect products from Adobe, Joomla, and Langflow, are reportedly being actively exploited in the wild.
The inclusion of these vulnerabilities in the KEV catalog mandates that federal agencies implement specific security measures to protect their networks. While CISA's directive specifically targets federal civilian executive branch agencies, it serves as a critical alert for all organizations to prioritize patching these flaws.
Among the newly added vulnerabilities is a flaw in Adobe Commerce. This issue, identified by CISA, is a critical security gap that could allow for unauthorized access or malicious code execution within affected Adobe Commerce instances.
Additionally, two vulnerabilities affecting Joomla, a popular content management system, have been added to the KEV catalog. These flaws, if exploited, could potentially compromise Joomla websites, leading to data breaches or defacement.
The fourth vulnerability concerns Langflow, an open-source framework for developing and orchestrating large language model applications. This addition highlights the growing cybersecurity concerns surrounding AI development tools, as vulnerabilities in such platforms could have significant implications for the security of AI-powered systems.
CISA has not provided specific details regarding the nature of the exploits or the actors behind them for these four vulnerabilities. However, the agency's inclusion in the KEV catalog signifies a high level of confidence that these flaws are being actively targeted by malicious actors.
Organizations using Adobe Commerce, Joomla, or Langflow are strongly advised to review their systems for these vulnerabilities and apply any available patches or mitigation strategies as soon as possible. Staying informed about and addressing vulnerabilities listed in the KEV catalog is a crucial step in maintaining a robust cybersecurity posture.
This action by CISA underscores the dynamic nature of the threat landscape and the importance of continuous vulnerability management and timely patching to defend against active exploitation.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.