July 8: CISA adds three CVEs to Known Exploited Vulnerabilities catalog

- CISA said on July 7 it added three actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-48908, CVE-2026-55255 and CVE-2026-56290. (cisa.gov) - The most notable entry was CVE-2026-55255, which CISA identified as a Langflow authorization-bypass flaw tied to a user-controlled key. (cisa.gov) - Federal civilian agencies must follow BOD 26-04 remediation requirements, and CISA’s KEV catalog remains available on the agency’s website. (cisa.gov)

CISA added three newly disclosed vulnerabilities to its Known Exploited Vulnerabilities catalog on July 7, saying the flaws had evidence of active exploitation. The entries were CVE-2026-48908 in JoomShaper SP Page Builder, CVE-2026-55255 in Langflow, and CVE-2026-56290 in Joomlack Page Builder, according to the agency’s alert. (cisa.gov) CISA said the additions were made under its process for tracking vulnerabilities that pose significant risk to federal networks. The KEV catalog is the agency’s list of vulnerabilities “that have been exploited in the wild,” CISA says. ### Which three vulnerabilities did CISA add? CISA’s July 7 alert named CVE-2026-48908 as a JoomShaper SP Page Builder unrestricted file upload flaw, CVE-2026-55255 as a Langflow authorization-bypass flaw, and CVE-2026-56290 as a Joomlack Page Builder improper access control flaw. (cisa.gov) The agency said each had evidence of active exploitation. The KEV catalog entry matters because CISA uses it as an authoritative list for vulnerabilities already being exploited, and the agency says organizations should use it as an input to vulnerability-management prioritization. CISA also publishes the catalog in web, CSV and JSON formats. (cisa.gov) ### Why did the Langflow entry draw attention? Langflow describes itself as a low-code builder for AI applications, including agents and Model Context Protocol workflows. CISA’s alert identified the Langflow issue as “Authorization Bypass Through User-Controlled Key,” making it the AI-related entry that drew the most attention in this batch. (cisa.gov) Langflow’s documentation says the project supports building and deploying AI agents and MCP servers, which helps explain why security researchers focused on its appearance in the KEV catalog. CISA did not characterize it beyond the vulnerability name in the July 7 alert. ### What does a KEV listing require federal agencies to do? (cisa.gov) Binding Operational Directive 26-04 sets vulnerability-management requirements for Federal Civilian Executive Branch agencies, CISA said in the alert. The directive requires agencies to prioritize rapid remediation of high-risk vulnerabilities, especially KEV-listed CVEs on publicly exposed assets that grant total control after exploitation, while allowing lower-risk items to be deferred. (cisa.gov) CISA said BOD 26-04 also establishes expectations for agencies to check whether threat actors compromised a system before a patch was applied. The agency said the directive applies to FCEB agencies, while urging all organizations to prioritize KEV remediation as part of risk-based vulnerability management. (langflow.org) ### How does CISA decide what goes into the catalog? CISA says potential additions to the KEV catalog must have a CVE identifier, evidence of exploitation and clear mitigation guidance. The agency invites outside submissions through its KEV nomination form and says it will continue adding vulnerabilities that meet the criteria. (cisa.gov) The catalog itself is described by CISA as the authoritative source of vulnerabilities exploited in the wild. The agency says stakeholders are responsible for evaluating each asset’s internet exposure and following BOD 26-04 patching guidance. ### Where can defenders track the next update? CISA maintains the KEV catalog on its website and publishes separate alert notices when new entries are added. (cisa.gov) The July 7 notice says agencies covered by BOD 26-04 must use the directive’s remediation framework, while other organizations are encouraged to use the catalog in their own prioritization process. CISA’s next step is the same one it outlines in each alert: continue adding vulnerabilities that meet its criteria, with updated entries and downloadable catalog files posted through the agency’s KEV pages. (cisa.gov 1) (cisa.gov 2)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.