CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

Key points
- The US Cybersecurity and Infrastructure Security Agency added four actively exploited flaws to its Known Exploited Vulnerabilities catalog on Tuesday.
- One of the bugs, CVE-2026-48282 in Adobe ColdFusion, carries the maximum severity score of 10.0.
- The other flaws affect Joomla and Langflow, an open-source tool used to build AI applications.
- US federal agencies must patch the flaws within the deadlines set by CISA under Binding Operational Directive 22-01.
- Private companies running the same software are strongly urged to apply fixes on the same timeline.
The US Cybersecurity and Infrastructure Security Agency, known as CISA, added four software flaws to its Known Exploited Vulnerabilities catalog, or KEV, on Tuesday. Getting onto that list means one thing: criminals are already using the flaw to break into real systems.
The catalog covers products from Adobe, Joomla and Langflow. We first reported on this ColdFusion vulnerability on 6 July, when roughly 800 servers sat exposed online after Canada's cyber agency raised the alarm. CISA's move this week puts a federal deadline on it.
What are the flaws, in plain English?
The most serious is a bug in Adobe ColdFusion, a platform businesses use to build web applications. Tracked as CVE-2026-48282, it scores a perfect 10.0 out of 10 on the standard severity scale.
It's a path traversal issue. An attacker tricks the server into opening or running files it should keep private, which can lead to arbitrary code execution: the attacker runs whatever program they choose on the victim's server. From there, customer data can be stolen or the server turned into a launchpad for further attacks.
The remaining three flaws cover Joomla, a widely used free website platform, and Langflow, an open-source tool developers use to wire up AI models into working applications. Langflow has been here before: our June story tracked CVE-2026-5027 hitting the same list, and Joomla's CVE-2026-48907 earned a CVSS 10.0 flag from CISA in June. CISA doesn't publish detailed attack write-ups at listing time, but inclusion in the KEV means it has seen real exploitation, not theoretical risk.
Should ordinary people worry?
Not directly, but the knock-on effects can reach anyone. A shop or clinic running an unpatched ColdFusion or Joomla site puts customer accounts and personal data at risk.
The familiar advice still applies: unique passwords managed by a password manager, two-factor authentication (a second code from your phone alongside a password) wherever it's offered. Two-factor authentication protects your account. It doesn't protect the company hosting it, because these are server-side flaws that land well before any login screen appears. The burden sits on the organisations running the vulnerable software.
What happens next?
Under Binding Operational Directive 22-01, every US federal civilian agency must patch anything on the KEV list by the deadline CISA sets, typically around three weeks. CISA also strongly urges private companies to follow the same schedule.
Admins running ColdFusion should check Adobe's security bulletins and apply updates immediately. Joomla site owners can update from the admin dashboard. Langflow users should pull the newest release from the project's official repository.
For the official record, see the National Vulnerability Database entry for CVE-2026-48282 and CISA's known exploited vulnerabilities page.
Attackers scan for unpatched servers within hours of a flaw going public. Patching fast isn't optional. It's the job.



