CVE-2026-48282Active Exploitation(adobe / coldfusion)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 32 mentions and remains active

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-22

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 105 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 138 mentions across 27 observed days

What's happening

  • Active exploitation reported across 105 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 64 signals
  • Technical details provided in 91 signals
  • Disclosure: 12 classified signals
  • General: 9 classified signals
  • Peaked 19d ago at 32 mentions (2026-07-08); latest day: 1
  • 138 total mentions across 27 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline138 mentions / 27d
08162432Mentions · 2026-06-30: 2Mentions · 2026-07-01: 3Mentions · 2026-07-02: 2Mentions · 2026-07-03: 2Mentions · 2026-07-04: 1Mentions · 2026-07-06: 24Mentions · 2026-07-07: 28Mentions · 2026-07-08: 32Mentions · 2026-07-09: 4Mentions · 2026-07-10: 7Mentions · 2026-07-11: 2Mentions · 2026-07-12: 3Mentions · 2026-07-13: 4Mentions · 2026-07-14: 1Mentions · 2026-07-15: 3Mentions · 2026-07-16: 2Mentions · 2026-07-17: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 2Mentions · 2026-07-20: 1Mentions · 2026-07-22: 6Mentions · 2026-07-23: 2Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-07: 3PoC Mentioned / Linked · 2026-07-08: 4PoC Mentioned / Linked · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-23: 1Exploit Tool / Code · 2026-07-07: 2Exploit Tool / Code · 2026-07-08: 3Exploit Tool / Code · 2026-07-23: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-07-04: 1Active Exploitation · 2026-07-06: 22Active Exploitation · 2026-07-07: 26Active Exploitation · 2026-07-08: 24Active Exploitation · 2026-07-09: 3Active Exploitation · 2026-07-10: 6Active Exploitation · 2026-07-12: 3Active Exploitation · 2026-07-13: 3Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-18: 1Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-22: 4Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-08-02: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-07-01: 3Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 2Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-06: 11Patch / Workaround · 2026-07-07: 12Patch / Workaround · 2026-07-08: 16Patch / Workaround · 2026-07-09: 3Patch / Workaround · 2026-07-10: 3Patch / Workaround · 2026-07-12: 2Patch / Workaround · 2026-07-13: 3Patch / Workaround · 2026-07-15: 2Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 3Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 2Technical Details · 2026-07-04: 1Technical Details · 2026-07-06: 13Technical Details · 2026-07-07: 14Technical Details · 2026-07-08: 22Technical Details · 2026-07-09: 4Technical Details · 2026-07-10: 6Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 2Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 3Technical Details · 2026-07-16: 2Technical Details · 2026-07-18: 1Technical Details · 2026-07-22: 6Technical Details · 2026-07-23: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-25: 106-3007-0207-0407-0707-0907-1107-1307-1507-1707-1907-2208-0208-0508-25
Signal classification6 categories
Active Exploitation
10475.4%
Disclosure
128.7%
General
96.5%
Patch
85.8%
PoC
42.9%
Exploit
10.7%
Referenced assets79 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-302
Disclosure1General1
2026-07-013
Patch3
2026-07-022
Active Exploitation1Disclosure1
2026-07-032
Active Exploitation1Disclosure1
2026-07-041
Active Exploitation1
2026-07-0624
Active Exploitation22General1PoC1
2026-07-0728
Active Exploitation26Exploit1PoC1
2026-07-0832
Active Exploitation24Disclosure1General2Patch3PoC2
2026-07-094
Active Exploitation3Patch1
2026-07-107
Active Exploitation6Patch1
2026-07-112
Disclosure1General1
2026-07-123
Active Exploitation3
2026-07-134
Active Exploitation3General1
2026-07-141
Disclosure1
2026-07-153
Active Exploitation2Disclosure1
2026-07-162
Active Exploitation1Disclosure1
2026-07-171
General1
2026-07-181
Active Exploitation1
2026-07-192
General2
2026-07-201
Active Exploitation1
2026-07-226
Active Exploitation3Disclosure3
2026-07-232
Active Exploitation2
2026-08-021
Active Exploitation1
2026-08-031
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-061
Disclosure1
2026-08-251
Active Exploitation1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-48282: PoC Path traversal vulnerability in Adobe ColdFusion's Remote Development Service (RDS) with a CVSS score of 10.0 GitHub: https://github.com/imbas007/CVE-2026-48282 https://t.co/MoyvDqIe6I

    Post summary

    A PoC path traversal vulnerability (CVE-2026-48282) in Adobe ColdFusion’s Remote Development Service has been disclosed with a GitHub repository providing the PoC and a CVSS score of 10.0.

    12401427029.3K
    234.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    🚨 Adobe ColdFusion flaw CVE-2026-48282 is now being exploited in the wild Attackers are exploiting a maximum-severity ColdFusion path traversal vulnerability that can lead to remote code execution on unpatched servers. The flaw affects ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Adobe patched it in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, with the issue carrying a CVSS score of 10.0. KEVIntel reported exploitation activity less than two hours after public details were released, including unauthenticated arbitrary file write and read attempts. ColdFusion bugs do not stay quiet for long. Patch exposed instances fast.

    Post summary

    ColdFusion CVE‑2026‑48282, a path traversal flaw with potential for remote code execution, is actively being exploited in the wild; Adobe’s patch has been released and exploitation activity was reported within hours of disclosure.

    350491116.1K
    233.2K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Adobe ColdFusion path traversal vulnerability CVE-2026-48282 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/47EcPjPikO

    Post summary

    The tweet alerts that Adobe ColdFusion path traversal CVE-2026-48282 is known to be exploited and directs organizations to mitigation steps.

    215040310.4K
    302.1K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Atacan vulnerabilidad crítica de Adobe ColdFusion aprovechando falla de máxima severidad El Centro Canadiense de Ciberseguridad advirtió que atacantes ya están explotando la vulnerabilidad de severidad máxima CVE-2026-48282 https://blog.elhacker.net/2026/07/atacan-vulnerabilidad-critica-de-adobe.html

    Post summary

    Canadian cybersecurity agency reports that attackers are already exploiting CVE-2026-48282 in Adobe ColdFusion, but no PoC, exploit tool, or patch details are included.

    0904085.0K
    141.7K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-48282 (CVSS 10.0): Active path traversal enables unauthenticated ColdFusion arbitrary code execution — actively exploited in the wild. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBZG9iZS1Db2xkRnVzaW9uIg%3D%3D 🎯161K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Adobe-ColdFusion" 🔖Refer: https://securityonline.info/coldfusion-arbitrary-code-execution/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE-2026-48282 is a high‑severity path traversal flaw in Adobe ColdFusion that allows unauthenticated arbitrary code execution and is being actively exploited in the wild, as evidenced by FOFA results and external references.

    111032124.2K
    14.7K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing highlights multiple CVEs under active exploitation—including two Microsoft zero‑days and a 2008 Cisco IOS flaw—while offering immediate patching guidance; no PoC or exploit code is shared.

    33032123.8K
    125.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-48282 - critical 🚨 Adobe ColdFusion - RDS Arbitrary File Write > ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitatio... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-48282 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2026‑48282, a critical arbitrary file write flaw in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier), has been announced with affected releases listed and a link to additional details.

    040981.4K
    1.3K followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Active Exploitation

    🚨Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network. Unauthenticated Arbitrary File Write & Read in Adobe ColdFusion Attacker location: India Attacker IP: 103.207.14[.]220 If you've not already patched, update immediately!

    Post summary

    Within hours of CVE-2026-48282 becoming public, KEVIntel detected real‑world exploitation of an unauthenticated arbitrary file write/read flaw in Adobe ColdFusion, and advises users to patch immediately.

    2201041.6K
    21.2K followersView on X
  • Aseem Shrey@AseemShrey
    Active Exploitation

    Adobe shipped a ColdFusion patch and one of the flaws was under active exploitation within hours of disclosure. CVE-2026-48282, a path traversal rated CVSS 10.0. The first attempt came from an India-geolocated IP probing for arbitrary file read against a Windows system file. The classic "can I read files off the box" test. And it wasn't alone. This was one of SEVEN CVSS 10.0 flaws in the same ColdFusion update. If you run ColdFusion, this one doesn't wait for your maintenance window.

    Post summary

    Adobe released a ColdFusion patch for CVE‑2026‑48282, a CVSS 10.0 path traversal flaw, which was actively exploited in the wild within hours of its disclosure.

    22084827
    8.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Adobe Systems Incorporated (CNA) ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Adobe ColdFusion 2025 Update 9 以前、および Adobe ColdFusion 2023 Update 20 以前に存在するパス・トラバーサルの脆弱性です。 制限されたディレクトリ外のパス処理が不適切であり、悪用により現在のユーザー権限のコンテキストで任意コード実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年7月10日 ・BOD 26-04 対処期限(露出なし):2026年7月21日 ✅攻撃前提条件 ・Adobe ColdFusion 2025 Update 9 以前、または Adobe ColdFusion 2023 Update 20 以前を使用している ・攻撃者が対象 ColdFusion 環境へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・ユーザー操作を必要としない ・Adobe ColdFusion 2025 Update 10、または Adobe ColdFusion 2023 Update 21 以降へ更新されていない ✅悪用時影響 ・制限されたディレクトリ外のファイルへアクセスされる可能性がある ・任意ファイルの読み取りまたは書き込みに悪用される可能性がある ・ColdFusion 環境上で任意コード実行につながる可能性がある ・機密性、完全性、可用性に高い影響が生じる ・ColdFusion サーバーを起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(Adobe) ・概要:Adobe は、CVE-2026-48282 が Adobe ColdFusion を標的とした限定的な攻撃で悪用されていることを公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-48282 ・https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html ・https://github.com/cisagov/vulnrichment/blob/develop/2026/48xxx/CVE-2026-48282.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282 ・https://github.com/imbas007/CVE-2026-48282 ・https://raw.githubusercontent.com/imbas007/CVE-2026-48282/main/CVE-2026-48282.py ・https://jvndb.jvn.jp/ja/cwe/CWE-22.html https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    Adobe ColdFusion path traversal CVE-2026-48282 is actively being exploited in the wild, with PoC and exploit code publicly available, and CISA has added it to its KEV catalog while Adobe has issued a patch advisory.

    0001157.4K
    44.2K followersView on X
  • SecurityWeek@SecurityWeek
    Active Exploitation

    CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/ (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)

    Post summary

    CISA warns that the vulnerabilities CVE-2026-48282, CVE-2026-55255, and CVE-2026-33017 in ColdFusion, Langflow, and Joomla are actively exploited and urges immediate patching.

    0201222.4K
    228.8K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-48282 PT ID: PT-2026-53903 Vendor: Adobe Product: ColdFusion Description: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-53903 • https://github.com/imbas007/CVE-2026-48282 #dbugs_vuln

    Post summary

    An exploitable PoC for Adobe ColdFusion Path Traversal CVE-202 Performance is publicly available, but there isDont see any evidence of active exploitation or an existing patch.

    020921.2K
    3.4K followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin enumerates several newly disclosed Adobe ColdFusion CVEs with emergency and critical ratings, but offers no PoC, exploit, patch, or technical detail.

    010111689
    227 followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz #Zafiyet: Adobe ColdFusion - Dizin Gezinme (Path Traversal) CVE Kodu: CVE-2026-48282 Zafiyet Türü: Dizin Gezinme / Sınırlandırılmış Dizin Dışına Çıkma (CWE-22) Fidye Yazılımı (Ransomware) Faaliyeti: Bilinmiyor 📌 Zafiyetin Özeti #Adobe #ColdFusion üzerinde, mevcut kullanıcının (current user) yetkileri bağlamında rastgele kod çalıştırılmasına (arbitrary code execution) yol açabilecek kritik bir dizin gezinme (path traversal) zafiyeti tespit edilmiştir. Bu güvenlik açığı, saldırganların kısıtlanmış dizinlerin dışına çıkarak yetkisiz dosyalara erişmesine ve sistem üzerinde zararlı kodları çalıştırmasına olanak tanıyabilir. 🛠️ Alınması Gereken Aksiyonlar 👉 Yama ve Güncelleme: Üretici tarafından yayınlanan güvenlik güncellemelerini ve hafifletici önlemleri (mitigations) ivedilikle test ve prod ortamlarınıza uygulayın. 👉 Risk ve Uyumluluk: CISA'nın BOD 26-04 (Risk Temelli Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Adli Bilişim Triyaj Gereksinimleri yönergelerine uygun hareket edin. 👉 Erişim Kontrolü: İlgili varlıkların internete maruz kalma durumunu (internet exposure) değerlendirin ve yetkisiz erişimleri engellemek için gerekli yapılandırmaları sağlayın. 👉 İzolasyon: Eğer bulut servisleri veya on-prem sistemler için geçerli bir yama veya hafifletici önlem henüz bulunmuyorsa, zafiyet giderilene kadar ürünün kullanımını durdurun veya dış ağ erişimini tamamen kısıtlayın.

    Post summary

    The post announces a CVE‑2026‑48282 path traversal flaw in Adobe ColdFusion, provides technical details, and stresses applying vendor patches and mitigations to mitigate risk, with no evidence of active exploitation or a PoC.

    02090157
    530 followersView on X
  • Akamai Security Intelligence Group@akamai_research
    Patch

    Akamai THR WAF team has proactively deployed an AAP Rapid Rule to protect our customers from a Critical Vulnerability in Adobe ColdFusion (CVE-2026-48282). Full writeup here: https://ow.ly/xIHS50ZlPgm

    Post summary

    Akamai has deployed a Rapid Rule to mitigate CVE‑2026‑48282, providing a patch/workaround for customers.

    001322.1K
    25.5K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    @ethicalhack3r #Adobe #ColdFusion flaw CVE-2026-48282 now exploited in the wild https://securityaffairs.com/194837/hacking/adobe-coldfusion-flaw-cve-2026-48282-now-exploited-in-the-wild.html #securityaffairs #hacking #AI

    Post summary

    The tweet claims CVE-2026-48282 is actively exploited in the wild, citing a news article but lacking technical or mitigation details.

    111302.0K
    37.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されている。 https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/

    Post summary

    Adobe has issued patches for several CVSS 10 ColdFusion and Campaign Classic vulnerabilities, marking a routine update cycle.

    102212.1K
    7.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Active Exploitation

    A critical CVSS 10 ColdFusion arbitrary code execution flaw (CVE-2026-48282) is actively exploited in the wild. Update immediately to prevent attacks. #ColdFusion #CVE202648282 #CyberSecurity #Vulnerability #Infosec http://securityonline.info/coldfusion-arbitrary-code-execution/

    Post summary

    The post warns that CVE‑2026‑48282, a critical ColdFusion arbitrary code execution vulnerability, is actively being exploited and urges users to apply available updates to mitigate the risk.

    00140797
    12.9K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-48282: A PoC has been released for an Adobe ColdFusion path traversal vulnerability that may lead to remote code execution (RCE) without user interaction. Affected versions include 2025.9, 2023.20, and earlier. 🔗 https://github.com/imbas007/CVE-2026-48282 #CyberSecurity #CVE #Adobe

    Post summary

    A proof‑of‑concept for CVE-2026-48282 has been published, demonstrating a path traversal that could enable remote code execution; no evidence of live attacks or vendor patches is mentioned.

    01030173
    1.3K followersView on X
  • Cert-IST@cert_ist
    Active Exploitation

    Les cybercriminels exploitent actuellement une faille de gravité maximale dans Adobe ColdFusion, identifiée par le numéro CVE-2026-48282, selon la société de veille sur les vulnérabilités KEVIntel. https://tinyurl.com/3d8usjes

    Post summary

    The post reports that cybercriminals are actively exploiting CVE-2026-48282 in Adobe ColdFusion, with no proof-of-concept, exploit code, or mitigation details shared.

    01021255
    961 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more