threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These vulnerabilities are being actively exploited in the wild, with evidence of exploitation occurring wi… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
vulnerability Hackers Exploit Langflow Vulnerability for Remote Code Execution Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on S… SecurityWeek · Jun 11, 2026 High CVE-2026-5027
vulnerability Path traversal flaw in AI dev platform Langflow exploited in attacks Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. BleepingComputer · Jun 10, 2026 High CVE-2026-5027CVE-2026-0770CVE-2026-21445
vulnerability Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated aut… The Hacker News · Jun 10, 2026 Critical CVE-2026-5027CVE-2026-0770CVE-2026-33017USCAlow-codeairemote code execution