Skip to content
eastbaycyber

CISA Adds 4 Known Exploited Vulnerabilities to Catalog (July 7, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On July 7, 2026, CISA added 4 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, CVE-2026-48282. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper · SP Page Builder

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Federal due date
2026-07-10
Ransomware use
Unknown
Added
2026-07-07

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow · Langflow

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

Federal due date
2026-07-10
Ransomware use
Unknown
Added
2026-07-07

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability

Joomlack · Page Builder

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

Federal due date
2026-07-10
Ransomware use
Unknown
Added
2026-07-07

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

Adobe · ColdFusion

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Federal due date
2026-07-10
Ransomware use
Unknown
Added
2026-07-07

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Adobe KEV history

Also added to KEV in July 2026

  • July 29, 2026: CVE-2026-20316, Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)
  • July 27, 2026: CVE-2026-16812, Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)
  • July 27, 2026: CVE-2025-68686, Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vuln)
  • July 22, 2026: CVE-2026-50522, Microsoft SharePoint (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability )
  • July 22, 2026: CVE-2026-16232, Check Point SmartConsole (Check Point SmartConsole Improper Authentication Vulnerability)
  • July 21, 2026: CVE-2026-63030, WordPress Core (WordPress Core Interpretation Conflict Vulnerability)
  • July 21, 2026: CVE-2026-60137, WordPress Core (WordPress Core SQL Injection Vulnerability)
  • July 21, 2026: CVE-2026-0770, Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)
  • July 21, 2026: CVE-2021-27137, DD-WRT DD-WRT (DD-WRT Stack-Based Buffer Overflow Vulnerability)
  • July 16, 2026: CVE-2026-58644, Microsoft SharePoint (Microsoft SharePoint Deserialization of Untrusted Data Vulnerability)
  • July 16, 2026: CVE-2026-39808, Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
  • July 16, 2026: CVE-2026-25089, Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)
  • July 15, 2026: CVE-2026-46817, Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)
  • July 15, 2026: CVE-2023-4346, KNX Association KNX Protocol Connection Authorization Option 1 (KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictiv)
  • July 14, 2026: CVE-2026-56164, Microsoft SharePoint Server (Microsoft SharePoint Server Missing Authentication for Critical Function Vulnera)
  • July 14, 2026: CVE-2026-56155, Microsoft Active Directory Federation Services (Microsoft Active Directory Federation Services Insufficient Granularity of Acces)
  • July 14, 2026: CVE-2026-15410, SonicWall SMA1000 Appliances (SonicWall SMA1000 Appliances Code Injection Vulnerability)
  • July 14, 2026: CVE-2026-15409, SonicWall SMA1000 Appliances (SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability)
  • July 13, 2026: CVE-2008-4128, Cisco IOS (Cisco IOS Cross-Site Request Forgery Vulnerability)
  • July 10, 2026: CVE-2026-56291, Balbooa Forms (Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability)
  • July 10, 2026: CVE-2026-48939, iCagenda iCagenda (iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability)
  • July 1, 2026: CVE-2026-45659, Microsoft SharePoint Server (Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability)

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.