Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-3066 | Unauthenticated Deserialization RCE in Adobe ColdFusion (BlazeDS) CVE-2017-3066 is a Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library bundled with Adobe ColdFusion, which handles the product's Flex/AMF remoting functionality. An unauthenticated remote attacker can trigger it by sending crafted serialized Java objects to the server's BlazeDS message broker endpoints over the network. Successful exploitation allows arbitrary code execution with the privileges of the ColdFusion service, and the critical CVSS 3.1 score of 9.8 reflects that no privileges, user interaction, or special conditions are required. Users of Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-24 alongside an Oracle flaw, its EPSS probability of exploitation within 30 days is 90.6% (100th percentile), and a public proof-of-concept exploit is available on Exploit-DB (43993). Do: Update all ColdFusion 10, 11, and 2016 servers beyond the affected update levels per Adobe's vendor guidance, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict or block network access to the BlazeDS/AMF remoting endpoints (the /flex2gateway endpoints) at the firewall or web server layer, since these are the attack surface for this flaw, and review access logs for anomalous requests to them. A public proof-of-concept (Exploit-DB 43993) shows unauthenticated exploitation, so treat exposed instances as high-priority; ransomware use is currently listed as unknown. | 9.8 | 91% | KEV PoC |
| largetens of thousands of internet-exposed ColdFusion servers (10k-100k range) | |
| CVE-2026-48282 | Path Traversal Leading to RCE in Adobe ColdFusion CVE-2026-48282 is a path traversal vulnerability (CWE-22) in Adobe ColdFusion. It is triggered by crafted file-path input containing directory-traversal sequences that the application fails to constrain, allowing access outside the intended directory; per CISA this can escalate to arbitrary code execution in the context of the current user. Successful exploitation could give an attacker the ability to run code on the ColdFusion host under the ColdFusion service account, a common foothold for further network compromise. All organizations running affected Adobe ColdFusion releases, particularly internet-facing instances, are in scope; the specific affected version ranges have not been detailed in the available data. The flaw is already being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-07 and carries a 42.4% EPSS probability of exploitation within 30 days (99th percentile), though no public PoC is known and ransomware use is unconfirmed. Do: Inventory all Adobe ColdFusion deployments, prioritizing internet-facing servers, and apply the vendor patch per Adobe's security advisory since the affected version ranges are not yet specified in this data. Federal agencies must patch or apply mitigations in accordance with CISA BOD 26-04 within the KEV deadline or discontinue use if mitigations are unavailable. Until patched, restrict external access to ColdFusion instances and consider WAF/IPS rules blocking directory-traversal sequences in file-path parameters. | 10.0 | 42% | KEV |
| largeon the order of tens of thousands of ColdFusion installations, with roughly 10,000-100,000 internet-exposed servers |
Full article261 words · extracted from securityaffairs.com · click to collapse

Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers.
Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that could result in arbitrary code execution without authentication. It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers to execute code on vulnerable servers.
The company warned that the vulnerability is easy to exploit and is likely to be exploited in attacks in the wild.
KEVIntel researchers reported that Less than two hours after details of CVE-2026-48282 became public, attackers started exploiting it in attacks in the wild.
KEVIntel founder Ryan Dewhurst reported that the attacks originated from the IP address 103.207.14[.]220 by an attacker located in India.
— Ryan Dewhurst (@ethicalhack3r) July 2, 2026🚨Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.
Unauthenticated Arbitrary File Write & Read in Adobe ColdFusion
Attacker location: India
Attacker IP: 103.207.14[.]220
Organizations running Adobe ColdFusion should install the latest security updates as soon as possible to protect their systems from ongoing attacks.
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Adobe ColdFusion Deserialization Vulnerability, tracked as CVE-2017-3066, to its Known Exploited Vulnerabilities (KEV) catalog.
Early this year, GreyNoise reported a coordinated campaign exploiting about a dozen Adobe ColdFusion vulnerabilities, with thousands of attack attempts observed during the Christmas 2025 holiday.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2026-48282)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194837/hacking/adobe-coldfusion-flaw-cve-2026-48282-now-exploited-in-the-wild.html