CISA's list that day

7 July 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Adobe ColdFusion, JoomShaper SP Page Builder, Langflow and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-48908Unrestricted Upload of File with Dangerous TypeJoomShaper SP Page BuilderPatch nowForensic triage required by CISA0.89
CVE-2026-48282Path TraversalAdobe ColdFusionPatch nowForensic triage required by CISA0.42
CVE-2026-56290Improper Access ControlJoomlack Page BuilderPatch nowForensic triage required by CISA0.31
CVE-2026-55255Authorization Bypass Through User-Controlled KeyLangflow LangflowPatch nowForensic triage required by CISA0.01

Other changes that day

  1. CVE-2025-3248 LangflowRansomware use: Unknown to Known.