hacker-news · Crawled Jul 8, 2026
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
3 IoCs 5 CVEs
Read original article ↗
AI Summary
CISA has added four actively exploited vulnerabilities in Adobe ColdFusion, Joomla Page Builder, and Langflow to its Known Exploited Vulnerabilities (KEV) catalog. Exploitation of these flaws, including path traversal and improper access control, has been observed in the wild, leading to remote code execution and unauthorized access. Attackers have deployed web shells and targeted AI orchestration platforms to steal credentials, with activity linked to opportunistic, financially motivated campaigns. Federal agencies are urged to patch by July 10, 2026.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 40 techniques
T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1619 Cloud Storage Object Discovery · Discovery T1053.003 Cron · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1075 T1075 T1490 Inhibit System Recovery · Impact T1070.004 File Deletion · Defense Evasion T1135 Network Share Discovery · Discovery