10/10 and full site capture in one click. In the extensions of Joomla and Langflow found critical vulnerabilities

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
242
Reaction score
305
Deposit
0$
The US authorities have warned of three vulnerabilities that attackers are already using in real attacks. The U.S. Cyber Security and Infrastructure Protection Agency has added dangerous errors to the vulnerability catalog and urged organizations to establish fixes as soon as possible.





The list includes the vulnerability CVE-2026-48908 (10.0 Critical) in the SP Page Builder extension for Joomla site management system. The error allows an outsider without an account to download an arbitrary file to the server, including malicious code in PHP, and then execute it. A successful attack gives full control of the site.





The second vulnerability, CVE-2026-55255 (9.9 Critical), touches the Langflow platform to create artificial intelligence-based applications. Due to the fact that the rights are checked incorrectly, the authorized attacker can specify the identifier of someone else's process and run it on behalf of the owner. As a result, the attacker is able to access the closed data, keys and other secrets stored in the system.





The third problem was called CVE-202-56290 (10.0 Critical) and was found in the Page Builder CK extension for Joomla. Insufficient access control allows you to download the executable file without authorization and run the code on the server. Such an attack can also allow you to completely capture the site.








All three vulnerabilities are already used in attacks, but the Agency has not disclosed who is attacking, what goals is pursued and how many systems have already been infected. Such errors are often used to infiltrate the system at the initial stage of the attack, especially when vulnerable sites and services are available from the Internet.





Federal corps of the United States is obliged to eliminate such vulnerabilities in the first place. Directive BOD 26-04 requires the rapid correction of errors from the catalog that affect open resources and allow you to completely capture the system. The agencies should also check whether the attackers have not had time to enter the infrastructure before the updates are installed.





The requirements of the directive apply only to US federal agencies, but the Agency recommends that all organizations take the same approach. Administrators should check for vulnerable extensions and platforms, establish available fixes, and examine the logs of events on the signs of the previous hack.
 
Top Bottom