CISA adds three CVEs to KEV Catalog
For exposed federal assets, the practical question is ownership speed, because CISA’s alert does not give the deadline.
TL;DR
CISA added CVE-2026-48908, CVE-2026-55255 and CVE-2026-56290 to the Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Federal Civilian Executive Branch agencies must prioritize rapid remediation under Binding Operational Directive 26-04 for qualifying publicly exposed assets. Contractors, primes and assessors using affected JoomShaper, Langflow or Joomlack products should treat the listing as an immediate vulnerability-management input, though CISA’s alert does not state a specific deadline.
CISA’s July 7 update adds three actively exploited vulnerabilities to the Known Exploited Vulnerabilities Catalog: CVE-2026-48908 in JoomShaper SP Page Builder, CVE-2026-55255 in Langflow and CVE-2026-56290 in Joomlack Page Builder. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of high-risk KEV-listed vulnerabilities on publicly exposed assets that would grant total control after exploitation, and must account for compromise checks before patching in the circumstances CISA identifies. For contractors and primes, the alert is less a new standalone mandate than a triage signal: find affected deployments, patch or mitigate under vendor instructions, and be ready to explain exposure and remediation status to the federal customer.
Published ·Deep Fathom