CVE-2026-48273Patch

MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-12); latest day: 2
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-12: 3Mentions · 2026-09-08: 1Mentions · 2026-09-09: 2Active Exploitation · 2026-09-08: 1Patch / Workaround · 2026-08-12: 2Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-08-12: 3Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 108-1209-0809-09
Signal classification2 categories
Patch
583.3%
Disclosure
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-123
Patch3
2026-09-081
Patch1
2026-09-092
Disclosure1Patch1
Full discourse6 posts
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 Adobe ColdFusion için CVSS 10.0 kritik RCE içeren güvenlik güncellemeleri yayınlandı! En kritik açık CVE-2026-48362. OS Command Injection olarak tanımlanan açık, kimlik doğrulama ve kullanıcı etkileşimi gerektirmeden uzaktan işletim sistemi komutlarının çalıştırılmasına izin veriyor. CVSS skoru 10.0! Güncellemede ayrıca CVSS 9.9 seviyesinde Eval Injection (CVE-2026-48273) ve çeşitli yetkilendirme, buffer overflow, XSS ve input validation açıkları dahil toplam 14 CVE gideriliyor. 🔴 Etkilenen sürümler: • ColdFusion 2025 -> 2025.0.11 ve öncesi • ColdFusion 2023 -> 2023.0.22 ve öncesi ✅ Güncel sürümler: • ColdFusion 2025.0.12 • ColdFusion 2023.0.23 Adobe, şu an için bu açıkların aktif olarak istismar edildiğine dair bir bilginin olmadığını belirtiyor. ColdFusion sunucuları için güncellemenin geciktirilmemesi özellikle önemli. 🔗 Adobe Security Bulletin: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.htm

    Post summary

    Adobe released critical security updates for ColdFusion, fixing 14 CVEs including a high‑severity RCE, and reaffirmed that no active exploitation has been observed.

    00020330
    2.4K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #ColdFusion Adobe から,Commerce で更新をリリース. 適用優先度「1」,緊急度には「Critical」 6 件. ・CVE-2026-48273 ・CVE-2026-75746 ・CVE-2026-75993 ・CVE-2026-75998 ・CVE-2026-75999 ・CVE-2026-76190 全 9 件. https://x.com/kawn2020/status/2097515258667839760

    Post summary

    Adobe issued a critical patch release for ColdFusion Commerce, addressing six CVEs designated as priority 1 under critical severity.

    1000054
    87 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe has released patches for 50+ vulnerabilities, including critical flaws in ColdFusion (CVE-2026-48362, CVE-2026-48273, CVE-2026-71384) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, CVE-2026-48381). These issues could enable arbitrary code execution or DoS. Commerce updates also address privilege escalation (CVE-2026-71362). With Priority 1 ratings, immediate patching is strongly advised.

    Post summary

    Adobe has released patches for multiple critical vulnerabilities in ColdFusion, Campaign Classic, and Commerce, emphasizing the need for immediate remediation to prevent potential arbitrary code execution, DoS, and privilege escalation.

    0001060
    38 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #ColdFusion ColdFusion 2025 2025.0.12 ColdFusion 2023 2023.0.23 ・CVE-2026-48362(CVSS 10.0) ・CVE-2026-48273(〃 9.9) ・CVE-2026-21279 ・CVE-2026-25652 ・CVE-2026-34635 ・CVE-2026-48386 ・CVE-2026-48440 ・CVE-2026-71384 つづく…

    Post summary

    The tweet enumerates several Adobe ColdFusion CVEs and references newer versions, indicating a security update, but does not provide PoC, exploit details, or evidence of active exploitation.

    1000051
    90 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL — Adobe ColdFusion CVE-2026-48273 CVSS 9.9 eval injection RCE allows low-privileged attackers to execute arbitrary code. Affected: ColdFusion 2025 (Update 12) & 2023 (Update 23) → https://threataft.com/articles/adobe-coldfusion-cve-2026-48273-eval-injection-rce #Adobe #ColdFusion #CVE #CVSS9 #PatchTuesday #ThreatIntel

    Post summary

    The post announces Adobe ColdFusion CVE‑2026‑48273 as a critical RCE via eval injection, providing technical details but no PoC, exploit code, or mitigation guidance.

    0000053
    43 followersView on X
  • Venkata Satish Guttula 🛰️@snakeyesV1
    Patch

    News: Adobe ships 170+ Sep patches. Campaign Classic CVE-2026-82004 (CVSS 10) OS command injection can run code; ColdFusion Priority 1 CVE-2026-48273 and CVE-2026-75746. Magento StyleSmuggler still in the wild. Apply Priority 1 within 3 days. https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/

    Post summary

    Adobe released a patch bundle that includes critical fixes for several CVEs, notes that one Adobe-related vulnerability remains actively exploited, and urges a timely application of the priority 1 patches.

    00000114
    3.0K followersView on X

Explore more