HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Adds Critical Adobe ColdFusion and Joomla Page Builder Flaws to KEV Catalog, Highlighting Active Exploits

CISA listed four CVEs—including a remote‑code‑execution flaw in Adobe ColdFusion—in its KEV catalog after attackers began exploiting them in the wild. Organizations must treat these as control‑gap alerts for SOC 2 readiness, ensuring rapid patching and documented remediation.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

CISA Adds Critical Adobe ColdFusion and Joomla Page Builder Flaws to KEV Catalog, Highlighting Active Exploits

What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed four newly‑disclosed vulnerabilities—CVE‑2026‑48282 (Adobe ColdFusion path‑traversal), CVE‑2026‑48908 (JoomShaper SP Page Builder unrestricted file upload), CVE‑2026‑55255 (Langflow authorization bypass), and CVE‑2026‑56290 (Joomlack Page Builder improper access control)—into its Known Exploited Vulnerabilities (KEV) catalog. Within hours of public disclosure, attackers began exploiting the ColdFusion flaw to achieve unauthenticated remote code execution, and web‑shells have been observed on Joomla sites using the Page Builder flaws.

Why It Matters for Compliance & Audit Readiness

  • These are actively exploited, high‑severity flaws that can bypass the very controls SOC 2 Security (CC6.1) and Availability (CC7.1) expect you to have in place.
  • Continuous evidence of vulnerability management (patch tracking, remediation verification) is a core audit artifact; missing or delayed patches become a control‑gap that auditors will flag.
  • Mapping each CVE to the relevant Control Mapping framework lets you demonstrate a defensible, real‑time remediation workflow—exactly the kind of evidence Verisq’s Control Mapping capability can surface for a SOC 2 audit.

Who Is Affected

  • Organizations running Adobe ColdFusion (e.g., enterprise web portals, B2B SaaS).
  • Websites built on Joomla with JoomShaper, Joomlack, or SP Page Builder plugins.
  • Deployments of Langflow (AI workflow orchestration) that expose the vulnerable API.

Recommended Actions

  • Inventory all assets running the listed products and versions.
  • Apply vendor patches immediately (ColdFusion 2025.9+, SP Page Builder 6.6.2+, Page Builder CK 3.6.0+).
  • Validate remediation by scanning for residual web‑shells or unauthorized admin accounts.
  • Document the remediation workflow in your SOC 2 control evidence repository (e.g., ticketing, change‑control logs).

Technical Notes

  • CVE‑2026‑48282: Path traversal → arbitrary code execution, CVSS 9.8, affects ColdFusion 2025.9, 2023.20, earlier.
  • CVE‑2026‑48908: Unrestricted PHP file upload → admin account creation, CVSS 8.6.
  • CVE‑2026‑55255: Authorization bypass via user‑controlled key, CVSS 7.9.
  • CVE‑2026‑56290: Improper access control in Joomlack Page Builder, CVSS 7.5.

Source: Security Affairs

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →