When vulnerability moves from a technical description to real attacks, the time for elimination is drastically reduced, and the U.S. Infrastructure Security and Infrastructure Protection Agency (CISA) has added in the catalog of known operated KEV vulnerabilities at once three new records.
CISA has received confirmation that the attackers are already using errors in JoomShaper SP Page Builder, Langflow and Joomlack Page Builder. The KEV catalog includes vulnerabilities, the operation of which was recorded in practice, and not only demonstrated in a test environment.
Vulnerability CVE-2026-48908 (9.8 on the CVSS 3.1) scale in JoomShaper SP Page Builder allows you to upload dangerous files without the necessary restrictions. CVE-2026-55255 (8.4 on the CVSS 3.1) scale in Langflow helps to bypass authorization using the key that the user controls. CVE-2026-56290 (9.8 on the CVSS 3.1) scale in Joomlack Page Builder is associated with incorrect access control and opens features that must be unavailable to outsiders.
Such errors give attackers the opportunity to penetrate publicly available systems and, in the most dangerous cases, to gain full control over them. CISA did not disclose information about specific attacks, affected organizations and the tools used by the attackers.
U.S. federal agencies must address vulnerabilities under BOD 26-04. The document requires, first of all, to protect the systems available from the Internet, the capture of which allows you to fully control the resource. Before installing updates, departments are also instructed to check whether the attackers have managed to compromise the infrastructure.
CISA recommends that all organizations use the same approach, quickly eliminate vulnerabilities from the KEV directory and check the systems for hacking signs before installing updates.
CISA has received confirmation that the attackers are already using errors in JoomShaper SP Page Builder, Langflow and Joomlack Page Builder. The KEV catalog includes vulnerabilities, the operation of which was recorded in practice, and not only demonstrated in a test environment.
Vulnerability CVE-2026-48908 (9.8 on the CVSS 3.1) scale in JoomShaper SP Page Builder allows you to upload dangerous files without the necessary restrictions. CVE-2026-55255 (8.4 on the CVSS 3.1) scale in Langflow helps to bypass authorization using the key that the user controls. CVE-2026-56290 (9.8 on the CVSS 3.1) scale in Joomlack Page Builder is associated with incorrect access control and opens features that must be unavailable to outsiders.
Such errors give attackers the opportunity to penetrate publicly available systems and, in the most dangerous cases, to gain full control over them. CISA did not disclose information about specific attacks, affected organizations and the tools used by the attackers.
U.S. federal agencies must address vulnerabilities under BOD 26-04. The document requires, first of all, to protect the systems available from the Internet, the capture of which allows you to fully control the resource. Before installing updates, departments are also instructed to check whether the attackers have managed to compromise the infrastructure.
CISA recommends that all organizations use the same approach, quickly eliminate vulnerabilities from the KEV directory and check the systems for hacking signs before installing updates.