CVE-2026-48313Disclosure(adobe / coldfusion)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-06-30); latest day: 2
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-07-28: 1Mentions · 2026-07-29: 2Active Exploitation · 2026-07-29: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 106-3007-0707-0807-1007-2807-29
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Patch
112.5%
Active Exploitation
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure1General1
2026-07-071
Disclosure1
2026-07-081
Disclosure1
2026-07-101
Patch1
2026-07-281
Disclosure1
2026-07-292
Active Exploitation1General1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-48313 - high 🚨 ColdFusion - Path Traversal > ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitatio... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-48313 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-48313 as a high‑severity path traversal flaw affecting certain ColdFusion versions, without mentioning a proof of concept, active exploitation, or patch.

    020751.7K
    1.3K followersView on X
  • Aretiq.AI@AretiqAI
    General

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin announces multiple emergency and critical CVEs for Adobe ColdFusion and IBM WebSphere Application Server without providing PoC, exploit, patch, or technical details.

    010111689
    227 followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    『NodeZero® was able to exploit CVE-2026-48283 and achieve host compromise in under 90 seconds.』😲 ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313 https://horizon3.ai/intelligence/blogs/coldfusion-critical-cves/

    Post summary

    NodeZero demonstrates that CVE-2026-48283 is actively exploited, achieving host compromise in under 90 seconds, highlighting real‑world usage of the vulnerability.

    00021373
    7.1K followersView on X
  • Horizon3.ai@Horizon3ai
    Disclosure

    The two CVEs in question: • CVE-2026-48283 (CVSS 10.0) • CVE-2026-48313 (CVSS 9.3) Both are unauthenticated. Neither requires user interaction. One enables file upload leading to remote code execution. The other enables path traversal to access sensitive files.

    Post summary

    The text discloses two high‑severity CVEs, noting their unauthenticated nature and how one leads to RCE via file upload while the other permits path traversal to sensitive files; it provides technical details but no PoC, exploit tool, or patch.

    10000101
    2.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Adobe ColdFusion 2025/2023 緊急アップデート:RCE などの深刻な 11件の脆弱性に対応 https://iototsecnews.jp/2026/07/01/adobe-coldfusion-critical-vulnerabilities-let-attackers-execute-arbitrary-code/ Adobe ColdFusion における、外部からの入力やファイルの不適切な取り扱いが、一連の問題の原因となっています。具体的には、制限のないファイルアップロードが可能な CVE-2026-48276 や CVE-2026-48283 、入力の検証が不十分な CVE-2026-48277 などの欠陥があります。また、不正なファイル読み込みにつながるパス・トラバーサルの CVE-2026-48282 や、不適切な入力検証による CVE-2026-48313 なども深刻な影響を及ぼします。これらの原因により、未認証の第三者が、サーバを完全に制御する可能性があります。ご利用のチームは、ご注意ください。 #Adobe #ColdFusion #CVE202648276 #CVE202648277 #CVE202648281 #CVE202648282 #CVE202648283 #CVE202648307 #CVE202648313 #CVE202648314 #CVE202648315 #CVE202648316 #Vulnerability

    Post summary

    The article announces multiple CVEs affecting Adobe ColdFusion, explains their technical nature and remote code execution risk, but provides no proof of concept, exploit code, or patch details.

    01000188
    500 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-48313: Adobe ColdFusion Path Traversal Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rdxF40

    Post summary

    The snippet cites CVE-2026-48313, a ColdFusion path‑traversal vulnerability, and links to an article about its business impact. No details on PoCs, exploits, patches, or active attacks are present.

    0000039
    32 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Adobe ColdFusion Critical Vulnerabilities Patched in Update https://meterpreter.org/adobe-coldfusion-critical-vulnerabilities/ "According to watchTowr, the arbitrary file write capability likely corresponds to CVE-2026-48282. Meanwhile, the arbitrary file read flaw aligns with CVE-2026-48313."

    Post summary

    The post announces that Adobe ColdFusion CVE-2026-48282 and CVE-2026-48313 have been patched, outlining file read/write vulnerabilities, but offers no evidence of exploitation or PoC.

    00000183
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48313 Path Traversal Vulnerability in Adobe ColdFusion 2025.9 a... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48313 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet reveals CVE-2026-48313 as a path traversal flaw in Adobe ColdFusion 2025.9 and supplies links to vulnerability details and alerts, but offers no PoC, exploit, or patch information.

    00000108
    4.1K followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more