【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/06-2026/07/12)

publish date : 2026-07-17 update date : 2026-07-17

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026071601073636 Publication Time 2026-07-16 13:05:37
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-16 13:05:37
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/06-2026/07/12)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000006

【CVE-2026-48908】JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability, allowing an unauthenticated user to upload arbitrary files, which may ultimately result in PHP code being uploaded and executed.

【CVE-2026-55255】Langflow Authorization Bypass Through User-Controlled Key Vulnerability (CVSS v3.1: 8.4)
【Whether exploited by ransomware: Unknown】Langflow contains an authentication bypass vulnerability, allowing an authenticated attacker to specify a victim’s workflow ID in a request and execute any workflow belonging to another user.

【CVE-2026-56290】Joomlack Page Builder Improper Access Control Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Joomlack Page Builder contains an improper access control vulnerability, which may allow an attacker to achieve remote code execution through unauthenticated arbitrary file uploads.

【CVE-2026-48282】Adobe ColdFusion Path Traversal Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Adobe ColdFusion contains a path traversal vulnerability, which may result in arbitrary code execution with the privileges of the current user.

【CVE-2026-56291】Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability, allowing unauthenticated arbitrary file uploads and resulting in remote code execution.

【CVE-2026-48939】iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】iCagenda contains an unrestricted upload of file with dangerous type vulnerability. An attacker may exploit the file attachment function to upload arbitrary files, ultimately resulting in PHP code being uploaded and executed.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-48908】Please refer to the listed affected versions https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/

【CVE-2026-55255】Please refer to the affected versions listed by the official vendor https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2

【CVE-2026-56290】Please refer to the listed affected versions https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/

【CVE-2026-48282】Please refer to the affected versions listed by the official vendor https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html

【CVE-2026-56291】Please refer to the listed affected versions https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/

【CVE-2026-48939】Please refer to the listed affected versions https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/

[Recommended Actions]

【CVE-2026-48908】A remediation update has been released for the vulnerability. Please update to the relevant version https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/

【CVE-2026-55255】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2

【CVE-2026-56290】A remediation update has been released for the vulnerability. Please update to the relevant version https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/

【CVE-2026-48282】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html

【CVE-2026-56291】A remediation update has been released for the vulnerability. Please update to the relevant version https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/

【CVE-2026-48939】A remediation update has been released for the vulnerability. Please update to the relevant version https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center