|
1 | 1 | { |
2 | 2 | "title": "CISA Catalog of Known Exploited Vulnerabilities", |
3 | | - "catalogVersion": "2026.07.01", |
4 | | - "dateReleased": "2026-07-01T19:00:06.9016Z", |
5 | | - "count": 1631, |
| 3 | + "catalogVersion": "2026.07.07", |
| 4 | + "dateReleased": "2026-07-07T18:28:17.8926Z", |
| 5 | + "count": 1635, |
6 | 6 | "vulnerabilities": [ |
| 7 | + { |
| 8 | + "cveID": "CVE-2026-48908", |
| 9 | + "vendorProject": "JoomShaper", |
| 10 | + "product": "SP Page Builder", |
| 11 | + "vulnerabilityName": "JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability", |
| 12 | + "dateAdded": "2026-07-07", |
| 13 | + "shortDescription": "JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.", |
| 14 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 15 | + "dueDate": "2026-07-10", |
| 16 | + "knownRansomwareCampaignUse": "Unknown", |
| 17 | + "notes": "https:\/\/extensions.joomla.org\/extension\/sp-page-builder\/ ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-48908", |
| 18 | + "cwes": [ |
| 19 | + "CWE-434" |
| 20 | + ] |
| 21 | + }, |
| 22 | + { |
| 23 | + "cveID": "CVE-2026-55255", |
| 24 | + "vendorProject": "Langflow", |
| 25 | + "product": "Langflow", |
| 26 | + "vulnerabilityName": "Langflow Authorization Bypass Through User-Controlled Key Vulnerability", |
| 27 | + "dateAdded": "2026-07-07", |
| 28 | + "shortDescription": "Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.", |
| 29 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 30 | + "dueDate": "2026-07-10", |
| 31 | + "knownRansomwareCampaignUse": "Unknown", |
| 32 | + "notes": "https:\/\/github.com\/langflow-ai\/langflow\/security\/advisories\/GHSA-qrpv-q767-xqq2 ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-55255", |
| 33 | + "cwes": [ |
| 34 | + "CWE-639" |
| 35 | + ] |
| 36 | + }, |
| 37 | + { |
| 38 | + "cveID": "CVE-2026-56290", |
| 39 | + "vendorProject": "Joomlack", |
| 40 | + "product": "Page Builder", |
| 41 | + "vulnerabilityName": "Joomlack Page Builder Improper Access Control Vulnerability", |
| 42 | + "dateAdded": "2026-07-07", |
| 43 | + "shortDescription": "Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.", |
| 44 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 45 | + "dueDate": "2026-07-10", |
| 46 | + "knownRansomwareCampaignUse": "Unknown", |
| 47 | + "notes": "https:\/\/www.joomlack.fr\/en\/joomla-extensions\/page-builder-ck ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-56290", |
| 48 | + "cwes": [ |
| 49 | + "CWE-284" |
| 50 | + ] |
| 51 | + }, |
| 52 | + { |
| 53 | + "cveID": "CVE-2026-48282", |
| 54 | + "vendorProject": "Adobe", |
| 55 | + "product": "ColdFusion", |
| 56 | + "vulnerabilityName": "Adobe ColdFusion Path Traversal Vulnerability", |
| 57 | + "dateAdded": "2026-07-07", |
| 58 | + "shortDescription": "Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.", |
| 59 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 60 | + "dueDate": "2026-07-10", |
| 61 | + "knownRansomwareCampaignUse": "Unknown", |
| 62 | + "notes": "https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-68.html ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-48282", |
| 63 | + "cwes": [ |
| 64 | + "CWE-22" |
| 65 | + ] |
| 66 | + }, |
7 | 67 | { |
8 | 68 | "cveID": "CVE-2026-45659", |
9 | 69 | "vendorProject": "Microsoft", |
|
4470 | 4530 | "shortDescription": "Langflow contains a missing authentication vulnerability in the \/api\/v1\/validate\/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.", |
4471 | 4531 | "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", |
4472 | 4532 | "dueDate": "2025-05-26", |
4473 | | - "knownRansomwareCampaignUse": "Unknown", |
| 4533 | + "knownRansomwareCampaignUse": "Known", |
4474 | 4534 | "notes": "This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: https:\/\/github.com\/advisories\/GHSA-c995-4fw3-j39m ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-3248", |
4475 | 4535 | "cwes": [ |
4476 | 4536 | "CWE-306" |
|
0 commit comments