Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory Alert TWCERTCC-200-202607-00000006
[Description]
【CVE-2026-48908】JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 JoomShaper SP Page Builder has an unrestricted upload of file with dangerous type vulnerability, allowing unauthenticated users to upload arbitrary files, which may ultimately lead to PHP code being uploaded and executed.
【CVE-2026-55255】Langflow Authorization Bypass Through User-Controlled Key Vulnerability (CVSS v3.1: 8.4)
【Whether exploited by ransomware: unknown】 Langflow has an authentication bypass vulnerability, allowing authenticated attackers to specify a victim’s workflow ID in the request and thereby execute any workflows belonging to other users.
【CVE-2026-56290】Joomlack Page Builder Improper Access Control Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 Joomlack Page Builder has an improper access control vulnerability, which may allow attackers to achieve remote code execution through unauthenticated arbitrary file upload.
【CVE-2026-48282】Adobe ColdFusion Path Traversal Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: unknown】 Adobe ColdFusion has a path traversal vulnerability, which may result in arbitrary code execution under the current user’s privileges.
【CVE-2026-56291】Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 Balbooa Forms has an unrestricted upload of file with dangerous type vulnerability, allowing unauthenticated arbitrary file upload, which may lead to remote code execution.
【CVE-2026-48939】iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 iCagenda has an unrestricted upload of file with dangerous type vulnerability. Attackers can exploit the file attachment function to upload arbitrary files, ultimately resulting in PHP code being uploaded and executed.
[Affected Platform]
【CVE-2026-48908】Please refer to the listed affected versions https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】Please refer to the affected versions listed by the official https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】Please refer to the listed affected versions https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】Please refer to the affected versions listed by the official https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】Please refer to the listed affected versions https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】Please refer to the listed affected versions https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
[Recommendations]
【CVE-2026-48908】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】 The official has released fixes for the vulnerability. Please update to the relevant versions https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】 The official has released fixes for the vulnerability. Please update to the relevant versions https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/