CISA adds KEV entries for actively exploited Adobe, Joomla, and Langflow flaws
Source headline: CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
Intelligence Summary
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog with four flaws that show evidence of active exploitation. The batch includes a critical path traversal issue in Adobe ColdFusion with a CVSS of 10.0. It also covers additional vulnerabilities affecting Joomla and Langflow. Being listed in KEV signals that organizations should treat these issues as urgent remediation priorities. System owners running the impacted products are advised to patch immediately and verify exposure.
Recommended Action
Check whether your CISA deployment is affected by CVE-2026-48282 (CVSS 10.0) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.