CVE-2026-48283General(adobe / coldfusion)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 7d ago at 2 mentions (2026-06-30); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline11 mentions / 8d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-08: 1Mentions · 2026-07-19: 2Mentions · 2026-07-24: 1Mentions · 2026-07-28: 2Mentions · 2026-07-29: 1Active Exploitation · 2026-07-28: 1Active Exploitation · 2026-07-29: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-24: 1Technical Details · 2026-07-28: 106-3007-0107-0207-0807-1907-2407-2807-29
Signal classification4 categories
General
436.4%
Disclosure
327.3%
Patch
218.2%
Active Exploitation
218.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-011
Patch1
2026-07-021
General1
2026-07-081
Patch1
2026-07-192
Disclosure1General1
2026-07-241
General1
2026-07-282
Active Exploitation1General1
2026-07-291
Active Exploitation1
Full discourse11 posts
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin serves as a straightforward disclosure of newly identified CVEs affecting Adobe ColdFusion, listing severity levels without providing any PoC, exploit details, or patch information.

    010111689
    227 followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    『NodeZero® was able to exploit CVE-2026-48283 and achieve host compromise in under 90 seconds.』😲 ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313 https://horizon3.ai/intelligence/blogs/coldfusion-critical-cves/

    Post summary

    The post asserts that NodeZero successfully leveraged CVE-2026-48283 in under 90 seconds, indicating active exploitation, but it lacks any technical description, patch information, or PoC details.

    00021373
    7.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48283 Unrestricted File Upload Vulnerability in Adobe ColdFusion 2025.9 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48283

    Post summary

    The text announces CVE-2026-48283, describing it as an unrestricted file upload vulnerability affecting Adobe ColdFusion 2025.9 and earlier, with a reference to a Vulmon vulnerability details page.

    01010118
    4.1K followersView on X
  • Horizon3.ai@Horizon3ai
    Active Exploitation

    When Horizon3 evaluated CVE-2026-48283, #NodeZero achieved host compromise in 1 minute, 27 seconds. Speed matters when attackers don't need credentials to get started.

    Post summary

    NodeZero reportedly exploited CVE‑2026‑48283, achieving host compromise in a minute and a half, indicating active exploitation in the wild with no patch or mitigation details provided.

    1000051
    2.9K followersView on X
  • Horizon3.ai@Horizon3ai
    General

    The two CVEs in question: • CVE-2026-48283 (CVSS 10.0) • CVE-2026-48313 (CVSS 9.3) Both are unauthenticated. Neither requires user interaction. One enables file upload leading to remote code execution. The other enables path traversal to access sensitive files.

    Post summary

    The announcement lists two high‑score, unauthenticated CVEs: one permits remote code execution via file upload, the other allows path traversal to access sensitive files.

    10000101
    2.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-48282: ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277…

    Post summary

    An emergency bulletin lists several CVEs (CVE‑2026‑48281, ‑48282, ‑48283, ‑48277) affecting Adobe ColdFusion AAS 16.3, but provides no exploit details, patch info, or technical description.

    1000045
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3

    Post summary

    The post simply lists emergency notifications for several Adobe Coldfusion CVEs without providing any additional details about exploitation, patches, or technical analysis.

    1000039
    326 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Adobe ColdFusion 2025/2023 緊急アップデート:RCE などの深刻な 11件の脆弱性に対応 https://iototsecnews.jp/2026/07/01/adobe-coldfusion-critical-vulnerabilities-let-attackers-execute-arbitrary-code/ Adobe ColdFusion における、外部からの入力やファイルの不適切な取り扱いが、一連の問題の原因となっています。具体的には、制限のないファイルアップロードが可能な CVE-2026-48276 や CVE-2026-48283 、入力の検証が不十分な CVE-2026-48277 などの欠陥があります。また、不正なファイル読み込みにつながるパス・トラバーサルの CVE-2026-48282 や、不適切な入力検証による CVE-2026-48313 なども深刻な影響を及ぼします。これらの原因により、未認証の第三者が、サーバを完全に制御する可能性があります。ご利用のチームは、ご注意ください。 #Adobe #ColdFusion #CVE202648276 #CVE202648277 #CVE202648281 #CVE202648282 #CVE202648283 #CVE202648307 #CVE202648313 #CVE202648314 #CVE202648315 #CVE202648316 #Vulnerability

    Post summary

    The article announces an emergency patch for 11 Adobe ColdFusion CVEs, detailing technical flaws like unrestricted file upload and path traversal that could allow unauthenticated attackers to gain server control.

    01000188
    500 followersView on X
  • CyberTLDR@CyberTLDR
    General

    2/3 The ColdFusion CVEs cover unrestricted file uploads (CVE-2026-48276, CVE-2026-48283), improper input validation (CVE-2026-48277, CVE-2026-48281), and path traversal (CVE-2026-48282). All rated 10.0 and all lead to remote code execution. #Adobe #PatchTuesday #AppSec

    Post summary

    The excerpt lists several newly disclosed ColdFusion CVEs, detailing their vulnerability vectors and severity, but does not provide evidence of exploitation, PoC, or patch information.

    1000085
    17 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-48283: Adobe ColdFusion Unrestricted File Upload Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04qK3zB0

    Post summary

    The article addresses the Adobe ColdFusion unrestricted file upload vulnerability (CVE-2026-48283) and discusses its business implications and response measures, but it does not provide evidence of PoC, exploits, active exploitation, or patch information.

    0000040
    32 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📁 Adobe ColdFusion has a CVSS 10 unauthenticated file upload flaw leading to RCE. Versions 2025.9, 2023.20 and earlier are affected. Patch immediately. CVE-2026-48283 #ColdFusion #infosec https://secalerts.co/vulnerability/CVE-2026-48283?utm_campaign=x https://t.co/9NzfvkOP9C

    Post summary

    The tweet announces a critical file upload flaw in Adobe ColdFusion that allows RCE and urges users to patch immediately; it lacks PoC or exploit details.

    0000068
    847 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more