[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCgZGxKh3YNWNdHNnFqgfeSg2Npuco0BCrUtbbpSikXk":3},{"id":4,"slug":5,"title":6,"excerpt":7,"content":8,"cover_image_url":9,"author":10,"published_at":11,"created_at":12,"updated_at":12,"is_published":13},"83c9d563-1bda-4b29-988d-12592bc359dd","cisa-kev-july-2026-critical-vulnerabilities","CISA KEV July 2026: Every Critical Vulnerability Added This Month","CISA added 6 new vulnerabilities to its Known Exploited Vulnerabilities catalog in July 2026. Microsoft SharePoint, Langflow, Adobe ColdFusion and three Joomla extensions are actively being exploited right now.","\u003Carticle>\n\u003Cp>The first week of July 2026 brought a fresh wave of confirmed exploitations to the CISA Known Exploited Vulnerabilities catalog. Six entries were added between July 1 and July 9, spanning enterprise collaboration platforms, AI orchestration tools, and CMS extensions. Here is a complete breakdown of every addition, what is being targeted, and what action is required.\u003C\u002Fp>\n\n\u003Ch2>CVE-2026-45659 — Microsoft SharePoint Server RCE (CVSS 8.8)\u003C\u002Fh2>\n\u003Cp>Added to the KEV catalog on July 1, 2026, this deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows any authenticated attacker with Site Member permissions to execute code remotely. No administrator privileges are required — a low-privilege account is sufficient to trigger remote code execution. Microsoft released patches in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Active exploitation has been attributed to Storm-2603, a threat actor known for deploying Warlock ransomware.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Action required:\u003C\u002Fstrong> Apply the May 2026 Microsoft security update immediately. Organizations running on-premises SharePoint should treat this as a critical emergency patch given confirmed ransomware deployment in active exploitation chains.\u003C\u002Fp>\n\n\u003Ch2>CVE-2026-55255 — Langflow Authorization Bypass (KEV added July 7)\u003C\u002Fh2>\n\u003Cp>Langflow, the open-source low-code platform for building AI agent workflows, contains an authorization bypass through user-controlled key vulnerability. An authenticated attacker can execute any flow belonging to another user simply by specifying the victim's flow ID in the request. Given that Langflow deployments often have privileged access to LLMs, APIs, and internal data sources, the blast radius of a successful exploitation is significantly wider than a typical web application vulnerability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Action required:\u003C\u002Fstrong> Update to a patched Langflow version immediately. Review audit logs for unauthorized flow executions. If Langflow is exposed to the internet, restrict access to internal networks only while patching.\u003C\u002Fp>\n\n\u003Ch2>CVE-2026-56290 — Joomlack Page Builder RCE (KEV added July 7)\u003C\u002Fh2>\n\u003Cp>Joomlack Page Builder for Joomla contains an improper access control vulnerability that allows unauthenticated arbitrary file upload, leading to remote code execution. No authentication is required — any attacker with network access to the Joomla instance can upload and execute arbitrary PHP code. Disable the extension immediately if no patch is available and audit the filesystem for recently uploaded PHP files in web-accessible directories.\u003C\u002Fp>\n\n\u003Ch2>CVE-2026-48908 — JoomShaper SP Page Builder File Upload RCE (KEV added July 7)\u003C\u002Fh2>\n\u003Cp>A second Joomla page builder extension hit the KEV catalog on the same day: JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability, also allowing unauthenticated arbitrary file upload and PHP code execution. The simultaneous exploitation of two separate Joomla page builder extensions suggests active automated scanning campaigns targeting this category of CMS extension rather than specific products.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Action required:\u003C\u002Fstrong> Apply vendor patches immediately. Audit for suspicious PHP files in upload directories. Consider temporarily disabling the extension on public-facing instances until patched.\u003C\u002Fp>\n\n\u003Ch2>CVE-2026-48282 — Adobe ColdFusion Path Traversal RCE\u003C\u002Fh2>\n\u003Cp>Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Adobe released patches via security bulletin APSB26-68. ColdFusion has historically been a high-value target for attackers given its prevalence in enterprise and government environments. Instances exposed to the internet should be considered potentially compromised until verified clean.\u003C\u002Fp>\n\n\u003Ch2>The pattern emerging in July 2026\u003C\u002Fh2>\n\u003Cp>The July KEV additions reinforce a trend visible throughout 2026: attackers are systematically targeting content management and workflow platforms that sit at the intersection of privileged access and business-critical operations. SharePoint provides enterprise-wide document access. Langflow controls AI agent workflows. Joomla page builders have direct filesystem write access. Each represents a platform where a single exploitation opens doors far beyond the immediate target system.\u003C\u002Fp>\n\u003Cp>Teams running any of these technologies should treat the KEV listing as a fire drill, not a scheduled maintenance item. Exploitation is confirmed and active.\u003C\u002Fp>\n\u003Cp>Monitor KEV-flagged CVEs across your stack in real time on \u003Ca href=\"https:\u002F\u002Feolcanary.com\">EOLCanary\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Farticle>","\u002Fblog\u002Fcisa-kev-july-2026.png","EOLCanary Team","2026-07-09T08:00:00+00:00","2026-07-09T14:47:30.240877+00:00",true]