Vulnerabilities · 69 days ago

ColdFusion Exposure Window Collapses to Hours

An exposed ColdFusion server can become a host foothold almost as soon as the flaw is public. The old assumption was that teams had time to validate before attackers showed up; this coverage says that window is now measured in hours, not days.

CVE-2026-48282 is a critical path traversal flaw in Adobe ColdFusion 2025 and 2023. Sources say it was being exploited in the wild within hours of disclosure, and the fixes are ColdFusion 2025 update 10 and ColdFusion 2023 update 21.

The bug lets a crafted request escape the restricted directory and put content where the server will trust it. That turns a file-handling mistake into code execution under the app user, so patching the app does not erase the risk on a server that was already reachable.

CVE-2026-48282

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: coldFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted…

CISA federal remediation date Jul 10

Timeline

Sources

5 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-12

Editions

Related stories