CISA's list that day
7 July 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Adobe ColdFusion, JoomShaper SP Page Builder, Langflow and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-48908Unrestricted Upload of File with Dangerous Type | JoomShaper SP Page Builder | Patch nowForensic triage required by CISA | 0.89 | ||
| CVE-2026-48282Path Traversal | Adobe ColdFusion | Patch nowForensic triage required by CISA | 0.42 | ||
| CVE-2026-56290Improper Access Control | Joomlack Page Builder | Patch nowForensic triage required by CISA | 0.31 | ||
| CVE-2026-55255Authorization Bypass Through User-Controlled Key | Langflow Langflow | Patch nowForensic triage required by CISA | 0.01 |