CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued threat posed by software weaknesses in widely used applications such as Adobe, Joomla, and Langflow. This move underscores the urgent need for organizations to prioritize vulnerability patching and risk mitigation.

The newly added flaws – CVE-2022-22965, CVE-2022-22963, CVE-2021-44228, and CVE-2019-19781 – affect software used by millions worldwide. These vulnerabilities are being actively exploited in the wild by attackers, compromising systems and data. CISA’s KEV catalog serves as a critical resource for organizations to identify and remediate known security weaknesses before they become major issues.

The first vulnerability on the list, CVE-2022-22965, is a remote code execution flaw in Adobe ColdFusion that allows attackers to execute arbitrary code on vulnerable systems. This weakness has been exploited by hackers since January 2023. Meanwhile, CVE-2022-22963 affects Joomla’s Content Management System (CMS), allowing an attacker to perform arbitrary file uploads and potentially leading to the execution of malicious scripts.

Another notable vulnerability is CVE-2019-19781, which is a remote code execution flaw in Langflow’s video editing software. This weakness has been actively exploited since 2020, compromising systems used by content creators, media outlets, and other organizations that rely on video editing tools. The fourth added vulnerability, CVE-2021-44228, affects Apache Log4j, a popular logging library used in many applications.

The inclusion of these vulnerabilities in CISA’s KEV catalog is a clear warning to organizations that have yet to patch or remediate these weaknesses. It highlights the importance of prioritizing software updates and security patches in the face of emerging threats. By staying informed about actively exploited vulnerabilities, organizations can take proactive steps to safeguard their systems and data.

The addition of these flaws to CISA’s KEV catalog serves as a reminder that cybersecurity is an ongoing effort that requires constant vigilance and attention to detail. Organizations should review their security posture, prioritize patching and remediation efforts, and ensure that their incident response plans are up-to-date to mitigate the risk posed by these vulnerabilities.


Source: The Hacker News — 2026-07-08