Threat intelligence, vulnerabilities, and defensive engineering
A critical vulnerability in Page Builder CK allows unauthenticated attackers to achieve full remote code execution, triggering urgent CISA intervention.
CISA has added a critical IDOR vulnerability in Langflow (CVE-2026-55255) to its KEV catalog, requiring immediate patching for all deployments prior to version 1.9.2.
CISA has added a critical remote code execution vulnerability in Joomla's SP Page Builder to its KEV catalog; immediate patching to version 6.6.2 is mandatory.