Attackers begin exploiting critical Adobe ColdFusion flaw CVE-2026-48282 shortly after patch release

Attackers are already using a newly patched Adobe ColdFusion bug to break into vulnerable servers. The flaw, CVE-2026-48282, is a critical path traversal issue rated 10.0 that can lead to arbitrary code execution in ColdFusion 2025 and 2023; Adobe fixed it on June 30 in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, and external reporting says exploitation began within hours of public disclosure.
Why it matters: Organizations running Adobe ColdFusion should treat this as an immediate patching priority because internet-facing servers may already be targeted. Apply Adobe's June 30 updates now and review exposed ColdFusion systems for signs of compromise.

Sources

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Ionut Arghire 2026.07.08 94% relevant
This article updates the same ColdFusion event by adding that CISA has now added CVE-2026-48282 to the KEV catalog and ordered federal agencies to patch by July 10.
CISA orders feds to patch max severity ColdFusion flaw by Friday
Sergiu Gatlan 2026.07.08 95% relevant
This is a direct update on the same underlying event: active exploitation of Adobe ColdFusion CVE-2026-48282. The new information is that CISA has now added the flaw to the KEV catalog and ordered U.S. federal civilian agencies to patch by Friday under BOD 26-04.
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
Ionut Arghire 2026.07.07 100% relevant
This article establishes a distinct tracked event: active exploitation of Adobe ColdFusion CVE-2026-48282 after Adobe's June 30 patch, which is not the same as the existing broader Adobe ColdFusion and Campaign Classic patch roundup.
← Back to all stories