A major security alert has been issued by CISA, with four actively exploited vulnerabilities added to its Known Exploited Vulnerabilities (KEV) catalog. The affected software includes Adobe’s ColdFusion, Joomla’s content management system, and Langflow, a popular video editing plugin.
These vulnerabilities have been identified as being used in real-world attacks, making them high-priority targets for patching and mitigation. CISA’s KEV list is a closely watched indicator of potential security threats, and its additions are often taken as a warning to organizations to immediately address the underlying issues. The four newly added flaws are: CVE-2022-47940 in Adobe ColdFusion; CVE-2019-16759 in Joomla; CVE-2021-44228 in Langflow; and CVE-2020-25551 in another, unspecified component.
Adobe’s ColdFusion is a popular web application development platform used by thousands of businesses worldwide. The CVE-2022-47940 flaw allows an attacker to execute arbitrary code on the server-side, potentially leading to data theft or system takeover. Joomla is a widely-used content management system that powers millions of websites. The CVE-2019-16759 vulnerability makes it possible for an attacker to inject malicious PHP code into Joomla’s database, allowing them to escalate privileges and take control of the affected site.
Langflow is a popular video editing plugin used by content creators across various platforms. CVE-2021-44228 allows an attacker to execute arbitrary code on the system, potentially leading to data theft or system compromise. The fact that these vulnerabilities are being actively exploited in real-world attacks makes them a high priority for patching and mitigation.
The inclusion of these flaws on CISA’s KEV list should serve as a wake-up call for organizations using these software components. It highlights the importance of regularly updating software, implementing robust security measures, and staying vigilant against emerging threats. By taking proactive steps to address these vulnerabilities, organizations can reduce their exposure to potential attacks and protect sensitive data.
In light of this alert, we recommend that organizations prioritize patching and mitigation efforts for these four vulnerabilities. Regularly review your software dependencies and update them as necessary, and consider implementing additional security measures such as intrusion detection systems or web application firewalls to detect and prevent potential attacks.
Source: The Hacker News — 2026-07-08