The U.S. Cybersecurity and Infrastructure Security Agency added a maximum-severity Adobe ColdFusion path traversal flaw, CVE-2026-48282, to its Known Exploited Vulnerabilities catalog on July 7, 2026, after researchers found exploitation began within roughly two hours of Adobe’s patch release.
Facts
| Field | Detail |
| CVE | CVE-2026-48282 |
| CVSS score | 10.0 (maximum severity) |
| Vulnerability type | Path traversal (CWE-22) |
| Affected versions | ColdFusion 2025 Update 9 and earlier; ColdFusion 2023 Update 20 and earlier |
| Added to CISA KEV catalog | July 7, 2026 |
| Internet-exposed instances tracked | Nearly 800, per Shadowserver (may include honeypots) |
Adobe released patches for Adobe ColdFusion in its APSB26-68 security bulletin, addressing 11 CVEs including CVE-2026-48282, a path traversal flaw that allows unauthenticated, network-based remote code execution in the context of the current user. The flaw affects ColdFusion 2025 Update 9 and earlier along with ColdFusion 2023 Update 20 and earlier. Adobe rated the issue as posing a high risk of exploitation and urged administrators to patch within 72 hours.
That warning proved accurate. According to KEVIntel founder Ryan Dewhurst, attackers began exploiting CVE-2026-48282 within about two hours of Adobe’s disclosure. The Canadian Centre for Cyber Security separately urged network defenders to secure their systems against ongoing attacks. Watchtowr Labs has since published a proof-of-concept exploit with a full root-cause analysis, and multiple national CERTs have issued alerts.

Figure 1. Attackers moved within hours of Adobe’s patch.
CISA’s compressed deadline
CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on July 7, 2026, triggering Binding Operational Directive 26-04, which requires U.S. Federal Civilian Executive Branch agencies to remediate. The remediation deadline fell on July 10, 2026, a three-day window that CISA reserves for vulnerabilities it judges to carry active or imminent exploitation risk. BOD 26-04 also directs agencies to check whether systems were compromised before the patch was applied, not simply to apply the patch and move on.
Why ColdFusion keeps drawing attackers
ColdFusion servers have long been a favored target for both opportunistic scanning and targeted intrusions because of how widely the platform is deployed in enterprise web applications, often with long uptimes and inconsistent patch cycles. Shadowserver’s scanning currently counts close to 800 internet-facing ColdFusion instances, though researchers caution that figure may include honeypots deployed specifically to study attacker behavior rather than genuine production servers.
What administrators should do
Apply Adobe’s APSB26-68 patch immediately if it has not already been deployed. Because exploitation began before most organizations could patch, treat any unpatched, internet-facing ColdFusion server as a probable compromise and run forensic triage in line with CISA’s guidance rather than assuming a clean patch closes the incident. Restrict external access to ColdFusion administration interfaces where the business does not require it.

Leave a Reply