CISA Adds Three Known Exploite... Note

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities are CVE-2026-48908 in JoomShaper SP Page Builder, CVE-2026-55255 in Langflow, and CVE-2026-56290 in Joomlack Page Builder. Exploited vulnerabilities are common attack methods that pose significant risks to federal systems. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize fixing vulnerabilities listed in the KEV Catalog, especially those allowing complete control after exploitation. This directive also requires agencies to check for compromises before patching. Although BOD 26-04 is for FCEB agencies, CISA recommends all organizations use a risk-based approach to vulnerability management. CISA will continue to update the KEV Catalog with new exploited vulnerabilities. Organizations can nominate potential additions for the KEV Catalog. Nominated vulnerabilities must have a CVE ID, proof of exploitation, and available mitigation steps.