Attackers are already using a newly patched Adobe ColdFusion bug to break into vulnerable servers. The flaw, CVE-2026-48282, is a critical path traversal issue rated 10.0 that can lead to arbitrary code execution in ColdFusion 2025 and 2023; Adobe fixed it on June 30 in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, and external reporting says exploitation began within hours of public disclosure.
Why it matters: Organizations running Adobe ColdFusion should treat this as an immediate patching priority because internet-facing servers may already be targeted. Apply Adobe's June 30 updates now and review exposed ColdFusion systems for signs of compromise.
Ionut Arghire
2026.07.08
94% relevant
This article updates the same ColdFusion event by adding that CISA has now added CVE-2026-48282 to the KEV catalog and ordered federal agencies to patch by July 10.
Sergiu Gatlan
2026.07.08
95% relevant
This is a direct update on the same underlying event: active exploitation of Adobe ColdFusion CVE-2026-48282. The new information is that CISA has now added the flaw to the KEV catalog and ordered U.S. federal civilian agencies to patch by Friday under BOD 26-04.
Ionut Arghire
2026.07.07
100% relevant
This article establishes a distinct tracked event: active exploitation of Adobe ColdFusion CVE-2026-48282 after Adobe's June 30 patch, which is not the same as the existing broader Adobe ColdFusion and Campaign Classic patch roundup.
← Back to all stories