ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Hackers Exploit Maximum Severity Adobe ColdFusion Flaw

highExploit / PoC exploited in the wildimportance 60CVE-2026-48282

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48282
Path Traversal Leading to RCE in Adobe ColdFusion

CVE-2026-48282 is a path traversal vulnerability (CWE-22) in Adobe ColdFusion. It is triggered by crafted file-path input containing directory-traversal sequences that the application fails to constrain, allowing access outside the intended directory; per CISA this can escalate to arbitrary code execution in the context of the current user. Successful exploitation could give an attacker the ability to run code on the ColdFusion host under the ColdFusion service account, a common foothold for further network compromise. All organizations running affected Adobe ColdFusion releases, particularly internet-facing instances, are in scope; the specific affected version ranges have not been detailed in the available data. The flaw is already being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-07 and carries a 42.4% EPSS probability of exploitation within 30 days (99th percentile), though no public PoC is known and ransomware use is unconfirmed.

Do: Inventory all Adobe ColdFusion deployments, prioritizing internet-facing servers, and apply the vendor patch per Adobe's security advisory since the affected version ranges are not yet specified in this data. Federal agencies must patch or apply mitigations in accordance with CISA BOD 26-04 within the KEV deadline or discontinue use if mitigations are unavailable. Until patched, restrict external access to ColdFusion instances and consider WAF/IPS rules blocking directory-traversal sequences in file-path parameters.

10.042% KEV
  • Adobe ColdFusion
largeon the order of tens of thousands of ColdFusion installations, with roughly 10,000-100,000 internet-exposed servers
Full article314 words · extracted from infosecurity-magazine.com · click to collapse

Adobe has urged ColdFusion customers to patch their instances immediately after at least one maximum severity flaw was reported as being exploited by attackers.

The software giant released patches for 11 CVEs on June 30 in the APSB26-68 bulletin. Six of these were given a CVSS score of 10.

Security researchers flagged that CVE-2026-48282 was being targeted within hours of the vulnerability being made public.

It’s a path traversal flaw in the popular web app development platform which could lead to arbitrary code execution.

Read more on Adobe flaws: New Vulnerabilities Found in Adobe ColdFusion

There are 775 exposed ColdFusion instances online, according to data from the ShadowServer Foundation.

CVE-2026-48282, and the other vulnerabilities listed in APSB26-68 were not in CISA’s Known Exploited Vulnerabilities catalog at the time of writing, but that will surely change.

The maximum severity bugs are particularly dangerous, as exploitation does not require user interaction.

Adobe Changes its Patching Cadence

Concerned about the impact AI is having on the exploitation window, Adobe announced in June that it would be moving from a monthly to twice-monthly publication of security advisories.

“Twice-monthly bulletins will enable us to keep pace with the era of frontier AI. More vulnerabilities found means more fixes to deploy and a once-a-month publication window is no longer fast enough to stay ahead of our adversaries,” explained Adobe chief security officer, Aanchal Gupta.

“This new cadence is the direct result of investing in improved vulnerability discovery. AI accelerates discovery, but resilience still rests on the fundamentals: visibility, layered controls, continuous monitoring, and the discipline to ship fixes quickly once they are found.”

Adobe said it is still not aware of any exploits in the wild for CVE-2026-48282 or other flaws published in the APSB26-68 bulletin.

However, it’s ColdFusion offering is a popular target for attackers. In 2023, threat actors targeted the platform in crypto-mining, DDoS and other attacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/exploit-maximum-severity-adobe/