CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These vulnerabilities are being actively exploited in the wild, with evidence of exploitation occurring within hours of public disclosure. Notably, a threat actor was observed leveraging these flaws – alongside another unauthenticated RCE vulnerability – to steal LLM and AWS keys, indicative of a sustained campaign targeting AI orchestration platforms and potentially leading to botnet and cryptojacking activity. Agencies are urged to apply the fixes by July 10, 2026.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
