Exploitation observed; activity peaked at 32 mentions and remains active
Immediate actions
Patch adobe coldfusion systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Active Exploitation24Disclosure1General2Patch3PoC2
2026-07-09
4
Active Exploitation3Patch1
2026-07-10
7
Active Exploitation6Patch1
2026-07-11
2
Disclosure1General1
2026-07-12
3
Active Exploitation3
2026-07-13
4
Active Exploitation3General1
2026-07-14
1
Disclosure1
2026-07-15
3
Active Exploitation2Disclosure1
2026-07-16
2
Active Exploitation1Disclosure1
2026-07-17
1
General1
2026-07-18
1
Active Exploitation1
2026-07-19
2
General2
2026-07-20
1
Active Exploitation1
2026-07-22
6
Active Exploitation3Disclosure3
2026-07-23
2
Active Exploitation2
2026-08-02
1
Active Exploitation1
2026-08-03
1
Active Exploitation1
2026-08-05
1
Active Exploitation1
2026-08-06
1
Disclosure1
2026-08-25
1
Active Exploitation1
>Full discourse20 posts
Dark Web Informer@DarkWebInformer·
PoC
🚨 CVE-2026-48282: PoC Path traversal vulnerability in Adobe ColdFusion's Remote Development Service (RDS) with a CVSS score of 10.0
GitHub: https://github.com/imbas007/CVE-2026-48282 https://t.co/MoyvDqIe6I
Post summary
A PoC path traversal vulnerability (CVE-2026-48282) in Adobe ColdFusion’s Remote Development Service has been disclosed with a GitHub repository providing the PoC and a CVSS score of 10.0.
🚨 Adobe ColdFusion flaw CVE-2026-48282 is now being exploited in the wild
Attackers are exploiting a maximum-severity ColdFusion path traversal vulnerability that can lead to remote code execution on unpatched servers.
The flaw affects ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier.
Adobe patched it in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, with the issue carrying a CVSS score of 10.0.
KEVIntel reported exploitation activity less than two hours after public details were released, including unauthenticated arbitrary file write and read attempts.
ColdFusion bugs do not stay quiet for long. Patch exposed instances fast.
Post summary
ColdFusion CVE‑2026‑48282, a path traversal flaw with potential for remote code execution, is actively being exploited in the wild; Adobe’s patch has been released and exploitation activity was reported within hours of disclosure.
🛡️We added Adobe ColdFusion path traversal vulnerability CVE-2026-48282 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/47EcPjPikO
Post summary
The tweet alerts that Adobe ColdFusion path traversal CVE-2026-48282 is known to be exploited and directs organizations to mitigation steps.
Atacan vulnerabilidad crítica de Adobe ColdFusion aprovechando falla de máxima severidad
El Centro Canadiense de Ciberseguridad advirtió que atacantes ya están explotando la vulnerabilidad de severidad máxima CVE-2026-48282
https://blog.elhacker.net/2026/07/atacan-vulnerabilidad-critica-de-adobe.html
Post summary
Canadian cybersecurity agency reports that attackers are already exploiting CVE-2026-48282 in Adobe ColdFusion, but no PoC, exploit tool, or patch details are included.
⚠️⚠️ CVE-2026-48282 (CVSS 10.0): Active path traversal enables unauthenticated ColdFusion arbitrary code execution — actively exploited in the wild.
🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBZG9iZS1Db2xkRnVzaW9uIg%3D%3D
🎯161K+ Results are found on http://en.fofa.info in the past year.
FOFA Query: app="Adobe-ColdFusion"
🔖Refer: https://securityonline.info/coldfusion-arbitrary-code-execution/
#OSINT#FOFA#CyberSecurity#Vulnerability
Post summary
CVE-2026-48282 is a high‑severity path traversal flaw in Adobe ColdFusion that allows unauthenticated arbitrary code execution and is being actively exploited in the wild, as evidenced by FOFA results and external references.
Daniel's Daily Threat Intel & CVE Briefing (from claude)
Tue 15 Jul 2026
Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today.
1. CISA KEV / Actively Exploited (lead)
CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media)
CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI)
CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer)
Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek)
2. Edge / Network Gear
Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle.
3. Microsoft / Windows / Active Directory
Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI)
CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first.
CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately.
CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models.
So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog.
4. Web / Cloud / DevOps
Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com)
Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI)
No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise.
Watch / developing
Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days.
Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched.
Sources:
CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs)
ZDI — July 2026 Security Update Review
BleepingComputer — July 2026 Patch Tuesday, 3 zero-days
Tenable — July 2026 Patch Tuesday analysis
The Hacker News — Adobe/Joomla/Langflow KEV additions
SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla
http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR
SC Media — CISA adds Cisco IOS flaw to KEV
Post summary
The briefing highlights multiple CVEs under active exploitation—including two Microsoft zero‑days and a 2008 Cisco IOS flaw—while offering immediate patching guidance; no PoC or exploit code is shared.
🚨 CVE-2026-48282 - critical 🚨
Adobe ColdFusion - RDS Arbitrary File Write
> ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitatio...
👾 https://cloud.projectdiscovery.io/library/CVE-2026-48282
@pdnuclei#NucleiTemplates#cve
Post summary
CVE‑2026‑48282, a critical arbitrary file write flaw in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier), has been announced with affected releases listed and a link to additional details.
🚨Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.
Unauthenticated Arbitrary File Write & Read in Adobe ColdFusion
Attacker location: India
Attacker IP: 103.207.14[.]220
If you've not already patched, update immediately!
Post summary
Within hours of CVE-2026-48282 becoming public, KEVIntel detected real‑world exploitation of an unauthenticated arbitrary file write/read flaw in Adobe ColdFusion, and advises users to patch immediately.
Adobe shipped a ColdFusion patch and one of the flaws was under active exploitation within hours of disclosure.
CVE-2026-48282, a path traversal rated CVSS 10.0. The first attempt came from an India-geolocated IP probing for arbitrary file read against a Windows system file. The classic "can I read files off the box" test.
And it wasn't alone. This was one of SEVEN CVSS 10.0 flaws in the same ColdFusion update. If you run ColdFusion, this one doesn't wait for your maintenance window.
Post summary
Adobe released a ColdFusion patch for CVE‑2026‑48282, a CVSS 10.0 path traversal flaw, which was actively exploited in the wild within hours of its disclosure.
Adobe ColdFusion path traversal CVE-2026-48282 is actively being exploited in the wild, with PoC and exploit code publicly available, and CISA has added it to its KEV catalog while Adobe has issued a patch advisory.
CISA warns that the vulnerabilities CVE-2026-48282, CVE-2026-55255, and CVE-2026-33017 in ColdFusion, Langflow, and Joomla are actively exploited and urges immediate patching.
A PoC/exploit has been discovered for vulnerability CVE-2026-48282
PT ID: PT-2026-53903
Vendor: Adobe
Product: ColdFusion
Description: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
References:
• https://dbugs.ptsecurity.com/vulnerability/PT-2026-53903
• https://github.com/imbas007/CVE-2026-48282
#dbugs_vuln
Post summary
An exploitable PoC for Adobe ColdFusion Path Traversal CVE-202 Performance is publicly available, but there isDont see any evidence of active exploitation or an existing patch.
The bulletin enumerates several newly disclosed Adobe ColdFusion CVEs with emergency and critical ratings, but offers no PoC, exploit, patch, or technical detail.
🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik#GüvenlikBülteni
Merhaba #Brolyz#Zafiyet: Adobe ColdFusion - Dizin Gezinme (Path Traversal)
CVE Kodu: CVE-2026-48282
Zafiyet Türü: Dizin Gezinme / Sınırlandırılmış Dizin Dışına Çıkma (CWE-22)
Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor
📌 Zafiyetin Özeti
#Adobe#ColdFusion üzerinde, mevcut kullanıcının (current user) yetkileri bağlamında rastgele kod çalıştırılmasına (arbitrary code execution) yol açabilecek kritik bir dizin gezinme (path traversal) zafiyeti tespit edilmiştir. Bu güvenlik açığı, saldırganların kısıtlanmış dizinlerin dışına çıkarak yetkisiz dosyalara erişmesine ve sistem üzerinde zararlı kodları çalıştırmasına olanak tanıyabilir.
🛠️ Alınması Gereken Aksiyonlar
👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın.
👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin.
👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz erişimleri engellemek için gerekli yapılandırmaları sağlayın.
👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.
Post summary
The post announces a CVE‑2026‑48282 path traversal flaw in Adobe ColdFusion, provides technical details, and stresses applying vendor patches and mitigations to mitigate risk, with no evidence of active exploitation or a PoC.
Akamai THR WAF team has proactively deployed an AAP Rapid Rule to protect our customers from a Critical Vulnerability in Adobe ColdFusion (CVE-2026-48282).
Full writeup here:
https://ow.ly/xIHS50ZlPgm
Post summary
Akamai has deployed a Rapid Rule to mitigate CVE‑2026‑48282, providing a patch/workaround for customers.
@ethicalhack3r#Adobe#ColdFusion flaw CVE-2026-48282 now exploited in the wild
https://securityaffairs.com/194837/hacking/adobe-coldfusion-flaw-cve-2026-48282-now-exploited-in-the-wild.html
#securityaffairs#hacking#AI
Post summary
The tweet claims CVE-2026-48282 is actively exploited in the wild, citing a news article but lacking technical or mitigation details.
A critical CVSS 10 ColdFusion arbitrary code execution flaw (CVE-2026-48282) is actively exploited in the wild. Update immediately to prevent attacks.
#ColdFusion#CVE202648282#CyberSecurity#Vulnerability#Infosec
http://securityonline.info/coldfusion-arbitrary-code-execution/
Post summary
The post warns that CVE‑2026‑48282, a critical ColdFusion arbitrary code execution vulnerability, is actively being exploited and urges users to apply available updates to mitigate the risk.
🚨 CVE-2026-48282: A PoC has been released for an Adobe ColdFusion path traversal vulnerability that may lead to remote code execution (RCE) without user interaction. Affected versions include 2025.9, 2023.20, and earlier.
🔗 https://github.com/imbas007/CVE-2026-48282
#CyberSecurity#CVE#Adobe
Post summary
A proof‑of‑concept for CVE-2026-48282 has been published, demonstrating a path traversal that could enable remote code execution; no evidence of live attacks or vendor patches is mentioned.
Les cybercriminels exploitent actuellement une faille de gravité maximale dans Adobe ColdFusion, identifiée par le numéro CVE-2026-48282, selon la société de veille sur les vulnérabilités KEVIntel.
https://tinyurl.com/3d8usjes
Post summary
The post reports that cybercriminals are actively exploiting CVE-2026-48282 in Adobe ColdFusion, with no proof-of-concept, exploit code, or mitigation details shared.