CVE-2026-48276Patch(adobe / coldfusion)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 12 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 4 mentions (2026-06-30); latest day: 1
  • 14 total mentions across 7 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 7d
01234Mentions · 2026-06-30: 4Mentions · 2026-07-01: 3Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-07-08: 2Mentions · 2026-07-13: 1Mentions · 2026-07-22: 1Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-06-30: 3Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-08: 2Technical Details · 2026-06-30: 4Technical Details · 2026-07-01: 3Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-07-08: 206-3007-0107-0207-0307-0807-1307-22
Signal classification4 categories
Patch
750.0%
Disclosure
428.6%
General
214.3%
Active Exploitation
17.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-304
Disclosure1Patch3
2026-07-013
Disclosure1Patch2
2026-07-022
Disclosure2
2026-07-031
Patch1
2026-07-082
Active Exploitation1Patch1
2026-07-131
General1
2026-07-221
General1
Full discourse14 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-48276 and other: A lot of vulnerabilities in Adobe ColdFusion, 6 of them are 10.0 rating 😱 The last Adobe security bulletin disclosed 6 RCE vulnerabilities in Adobe ColdFusion with highest severity and other critical issues such as arbitrary file read and privilege escalation. 👉 https://nt.ls/GxXdK

    Post summary

    The recent Adobe bulletin reports six high‑severity RCE vulnerabilities in ColdFusion, including arbitrary file read and privilege escalation, with no mention of PoC, exploitation, patches, or false positives.

    0301031.6K
    7.7K followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin announces a set of newly disclosed Adobe ColdFusion and IBM WebSphere vulnerabilities, marking them as emergency or critical, but provides no PoC, exploit code, or patch information.

    010111689
    227 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されている。 https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/

    Post summary

    The post announces that Adobe has released patches for seven high‑severity ColdFusion vulnerabilities and one Campaign Classic flaw, providing CVE identifiers and CVSS scores but no evidence of exploitation or PoC.

    102212.1K
    7.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-48282 ❗ CVE-2026-48277 ❗ CVE-2026-48276 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-6/ https://t.co/OikXx2L4Fk

    Post summary

    The tweet lists several Adobe CVEs and directs users to external pages for more information but provides no further technical or operational details.

    00020289
    6.7K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: #CVE-2026-48276 (CVSS: 10) in #Adobe #ColdFusion is now #ActivelyExploited. Successful exploitation can lead to full server takeover! https://ccb.belgium.be/advisories/warning-adobe-patches-11-coldfusion-flaws-led-cve-2026-48276-cvss-100-rce-patch #Patch #Patch #Patch

    Post summary

    The message warns that CVE‑2026‑48276, a high‑severity RCE in Adobe ColdFusion, is actively exploited with potential for full server takeover, and urges immediate patching.

    02000372
    7.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-48276 — CVSS 10/10 ██████████ ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Ffm8cfOP4a

    Post summary

    The tweet announces CVE‑2026‑48276, a critical unrestricted file‑upload flaw in ColdFusion, and notes that a patch is now available.

    11000147
    63 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Adobe ColdFusion 2025/2023 緊急アップデート:RCE などの深刻な 11件の脆弱性に対応 https://iototsecnews.jp/2026/07/01/adobe-coldfusion-critical-vulnerabilities-let-attackers-execute-arbitrary-code/ Adobe ColdFusion における、外部からの入力やファイルの不適切な取り扱いが、一連の問題の原因となっています。具体的には、制限のないファイルアップロードが可能な CVE-2026-48276 や CVE-2026-48283 、入力の検証が不十分な CVE-2026-48277 などの欠陥があります。また、不正なファイル読み込みにつながるパス・トラバーサルの CVE-2026-48282 や、不適切な入力検証による CVE-2026-48313 なども深刻な影響を及ぼします。これらの原因により、未認証の第三者が、サーバを完全に制御する可能性があります。ご利用のチームは、ご注意ください。 #Adobe #ColdFusion #CVE202648276 #CVE202648277 #CVE202648281 #CVE202648282 #CVE202648283 #CVE202648307 #CVE202648313 #CVE202648314 #CVE202648315 #CVE202648316 #Vulnerability

    Post summary

    The post announces an emergency update for Adobe ColdFusion, detailing 11 critical CVEs that enable unauthenticated attackers to gain full server control.

    01000188
    500 followersView on X
  • CyberTLDR@CyberTLDR
    Disclosure

    2/3 The ColdFusion CVEs cover unrestricted file uploads (CVE-2026-48276, CVE-2026-48283), improper input validation (CVE-2026-48277, CVE-2026-48281), and path traversal (CVE-2026-48282). All rated 10.0 and all lead to remote code execution. #Adobe #PatchTuesday #AppSec

    Post summary

    The post announces five ColdFusion CVEs (unrestricted file uploads, improper input validation, and path traversal), all rated 10.0 and leading to remote code execution. No PoC, exploit code, or evidence of active exploitation is mentioned.

    1000085
    17 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-48276: Adobe ColdFusion Unrestricted File Upload Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04qqhkZ0

    Post summary

    The content is only a headline that references CVE‑2026‑48276, providing no detailed information about exploits, patches, or technical severity.

    0000044
    32 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Adobe patches 11 #ColdFusion flaws, led by CVE-2026-48276 CVSS 10.0 #RCE, plus several more critical CVSS 10.0 bugs. More info at: https://ccb.belgium.be/advisories/warning-adobe-patches-11-coldfusion-flaws-led-cve-2026-48276-cvss-100-rce-patch #Patch #Patch #Patch

    Post summary

    The advisory highlights that Adobe ColdFusion has issued patches for 11 critical flaws, notably CVE-2026-48276 (CVSS 10.0, RCE), and directs users to the patch info via the provided link.

    00000331
    7.2K followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by critical security vulnerabilities that can be exploited by attackers without privileges to gain remote code execution on unpatched systems. - CVE-2026-48276 - CVE-2026-48277 - CVE-2026-48281 - CVE-2026-48316 - CVE-2026-48282 Resolution for Cold Fusion lies in updating CF 2023 to Update 21 and CF 2025 to Update 10.

    Post summary

    Adobe ColdFusion versions before the outlined update levels carry critical CVEs that allow remote code execution; vendors recommend applying the specified updates to mitigate the risk.

    0000072
    22 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 CRITICAL: Adobe ColdFusion 3-CVE Cluster — CVSS 10.0 + 8.8 CVE-2026-48276: Unrestricted upload RCE (10.0) CVE-2026-48277: Input validation RCE (10.0) CVE-2026-48307: Reflected XSS (8.8) 🔗 https://threataft.com/articles/adobe-coldfusion-cve-2026-48276-48277-48307 #CyberSecurity #ThreatIntel #infosec #ColdFusion

    Post summary

    The tweet announces three critical Adobe ColdFusion CVEs—two RCEs and one XSS—with high CVSS scores, linking to an article but lacking PoC, exploit, patch, or active exploitation details.

    00000106
    31 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - ColdFusion unrestricted file upload leads to RCE (CVE-2026-48276) Adobe ColdFusion is vulnerable to an unrestricted upload of files with dangerous types, impacting ColdFusion 2025.9 and 2023.20 and earlier. The root cause is improper input validation/content-type enforcement (unrestricted file upload) allowing attacker-controlled files to be stored and executed. An attacker can exploit this remotely by sending a crafted upload request to a reachable ColdFusion endpoint, with no user interaction required and under typical web app privileges. Successful exploitation results in arbitrary code execution in the context of the current service/user, enabling full server compromise, lateral movement, and data theft. 👉 Affected: Adobe ColdFusion 2025.9 and earlier; 2023.20 and earlier | Upgrade to Adobe ColdFusion 2025.10 / 2023.21 (or later)

    Post summary

    Adobe ColdFusion 2025.9 and 2023.20 and earlier are vulnerable to an unrestricted upload that can lead to remote code execution; upgrading to 2025.10 or 2023.21 mitigates the issue.

    00000112
    232 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Adobe ColdFusion has a CVSS 10 critical flaw. CVE-2026-48276 allows unauthenticated arbitrary file upload leading to remote code execution. Versions 2025.9, 2023.20 and earlier are affected. Patch now. 📁 #ColdFusion #infosec https://secalerts.co/vulnerability/CVE-2026-48276?utm_campaign=x https://t.co/C71pmnKhs5

    Post summary

    A critical Adobe ColdFusion vulnerability (CVE‑2026‑48276) with a CVSS score of 10 allows unauthenticated file upload and RCE; affected versions are listed and a patch is immediately recommended.

    0000089
    847 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more