VORANT. Threat Intelligence Sign in Get the full feed

CISA KEV Adds JoomShaper, Langflow, Joomlack Flaws

medium vulnerability government-national

CISA added three actively exploited vulnerabilities in JoomShaper SP Page Builder, Langflow, and Joomlack Page Builder to its Known Exploited Vulnerabilities catalog.

CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with three new entries based on confirmed evidence of active exploitation: a file upload vulnerability in JoomShaper SP Page Builder, an authorization bypass in Langflow tied to user-controlled key handling, and an improper access control flaw in Joomlack Page Builder. These vulnerability classes are commonly abused attack vectors and pose elevated risk to internet-facing assets across federal and private-sector environments.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those enabling full asset compromise, and to verify whether systems were compromised prior to patching. While the directive is binding only on FCEB agencies, CISA recommends all organizations adopt similar risk-based patching practices for these three CVEs and other KEV entries.

No specific threat actor, malware, or campaign has been attributed to the exploitation of these vulnerabilities in this alert; the notice serves primarily as a remediation directive rather than a detailed technical advisory.

Mentioned in this report

Vulnerabilities CVE-2026-48908KEVCVE-2026-55255KEVCVE-2026-56290KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free