cisa-kev
CISA KEVExtracts: CVE id, vendor, due date · metadata or bounded excerpt
Retention: D1 event history with canonical source link and deduplication metadata.
Access basis: Public endpoint; no project credential required.
Last ingested: 2026-08-26 · run status: success with data
CVE: CVE-2026-48282 Vendor/project: Adobe Product: ColdFusion Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-22 Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required
- 2026-07-07CISA KEV: Joomlack / Page Builder / Joomlack Page Builder Improper Access Control Vulnerability
CVE: CVE-2026-56290 Vendor/project: Joomlack Product: Page Builder Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-284 Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbit
CVE: CVE-2026-55255 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-639 Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow b
CVE: CVE-2026-48908 Vendor/project: JoomShaper Product: SP Page Builder Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-434 JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users