CVE-2026-48282
Known exploited · CISA KEV
CVSS 10 CRITICAL: coldFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted…
CISA federal remediation date Jul 10
Vulnerabilities · 69 days ago
An exposed ColdFusion server can become a host foothold almost as soon as the flaw is public. The old assumption was that teams had time to validate before attackers showed up; this coverage says that window is now measured in hours, not days.
CVE-2026-48282 is a critical path traversal flaw in Adobe ColdFusion 2025 and 2023. Sources say it was being exploited in the wild within hours of disclosure, and the fixes are ColdFusion 2025 update 10 and ColdFusion 2023 update 21.
The bug lets a crafted request escape the restricted directory and put content where the server will trust it. That turns a file-handling mistake into code execution under the app user, so patching the app does not erase the risk on a server that was already reachable.
Known exploited · CISA KEV
CVSS 10 CRITICAL: coldFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted…
CISA federal remediation date Jul 10
5 sources covering this story
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10.
Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) - Help Net Security
CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers.
Path Traversal en ColdFusion de Adobe
Adobe ha publicado una vulnerabilidad de severidad crítica que encaso de ser explotada podría provocar
Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
Threat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0
Max severity Adobe ColdFusion flaw now exploited in attacks
Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel.
Part of the PlainSec briefing for 2026-07-12