ColdFusion Exposure Window Collapses to Hours

An exposed ColdFusion server can become a host foothold almost as soon as the flaw is public. The old assumption was that teams had time to validate before attackers showed up; this coverage says that window is now measured in hours, not days. CVE-2026-48282 is a critical path traversal flaw in Adobe ColdFusion 2025 and 2023. Sources say it was being exploited in the wild within hours of disclosure, and the fixes are ColdFusion 2025 update 10 and ColdFusion 2023 update 21. The bug lets a crafted request escape the restricted directory and put content where the server will trust it. That turns a file-handling mistake into code execution under the app user, so patching the app does not erase the risk on a server that was already reachable.

Part of the PlainSec briefing for 2026-07-12

Sources