AI description
CVE-2026-48282 is identified as a path traversal vulnerability affecting Adobe ColdFusion versions 2025.9, 2023.20, and earlier releases. This flaw, categorized as an Improper Limitation of a Pathname to a Restricted Directory (CWE-22), allows an attacker to execute arbitrary code in the context of the current user. Exploitation of CVE-2026-48282 does not require user interaction or any specific privileges, making it accessible over a network by sending crafted HTTP requests to a ColdFusion endpoint. Attackers can manipulate file system paths using traversal sequences to access or write files outside of the intended restricted directory, which can then be chained to achieve arbitrary code execution. This vulnerability has been observed under active exploitation shortly after its public disclosure.
- Description
- ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- Source
- psirt@adobe.com
- NVD status
- Analyzed
- Products
- coldfusion
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Adobe ColdFusion Path Traversal Vulnerability
- Exploit added on
- Jul 7, 2026
- Exploit action due
- Jul 10, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@adobe.com
- CWE-22
- Hype score
- Not currently trending
Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is exploited in the wild. Patched June 30 (APSB26-68); added to CISA KEV July 7. Unauthenticated RCE where RDS is enabled with auth disabled. Affected: 2025 ≤Update 9, 2023 ≤Update 20; fixed in Update 10/21.
@InfosecDotWatch
13 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-48282 ❗ CVE-2026-48277 ❗ CVE-2026-48276 ➡️ Más info: https://t.co/KWl5pRIS2P https://t.co/OikXx2L4Fk
@CERTpy
13 Jul 2026
221 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
⏰ Admins — the CISA KEV deadline was July 10. Did you patch these 4 actively exploited flaws? 🔹 CVE-2026-48282 — Adobe ColdFusion path traversal → code execution 🔹 CVE-2026-56290 — Joomlack Page Builder unauthenticated upload → RCE 🔹 CVE-2026-55255 — Langf
@techepages
13 Jul 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...
@Joe_Biden_ja
11 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
AdobeのWebアプリケーションサーバー「ColdFusion」のCVE-2026-48282は、6月30日の修正公開からわずか2日後にCCCS(カナダサイバーセキュリティセンター)が実環境での悪用報告を警告し、7月7日にはCISAもKEV(悪用確認
@MalwareBibleJP
10 Jul 2026
1431 Impressions
0 Retweets
8 Likes
2 Bookmarks
0 Replies
0 Quotes
800+ ColdFusion servers exposed. CVE-2026-48282 (CVSS 10.0) exploited within 2 hours of disclosure. CISA patch deadline is TODAY. Patch to 2025 Update 10 or disable RDS now. https://t.co/hi6Gy04edk #ColdFusion #CVE202648282 #CISAKOV #PatchNow #CyberSecurity https://t.co/ElrS5Jelj
@DecryptionDigst
10 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Adobe Systems Incorporated (CNA) ・種別:パス・ト
@piyokango
8 Jul 2026
5796 Impressions
0 Retweets
9 Likes
7 Bookmarks
0 Replies
0 Quotes
After analyzing 28% of vulnerabilities from past week, CVE-2026-48282 has 19 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert
@stooee_
8 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-48282: Unauthenticated path traversal in Adobe ColdFusion allows RCE. Affects 2025.x up to 2025.9, 2023.x up to 2023.20. Actively exploited; patches via APSB26-68. Disable RDS if not needed.
@GreyZoneSec
8 Jul 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-48282 Adobe ColdFusion, CVSS 10.0 Path traversal dans le RDS (FILEIO) → lecture/écriture de fichiers arbitraires sans auth → RCE. Déjà exploité dans la nature, ajouté au KEV CISA. Patchez : CF 2025 U10 / 2023 U21. Coupez le RDS si pas utilisé. PoC 👇
@Sn0wAlice
8 Jul 2026
249 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
It's Already When. — Field Note Active exploitation of max-severity ColdFusion (CVE-2026-48282), Langflow, and Gitea (CVE-2026-20896) flaws, plus GhostLock (CVE-2026-43499)... https://t.co/89LSZTiW9G #CyberSecurity #BlueTeam
@itsalreadywhen
8 Jul 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://t.co/rnuxt9VXQm (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)
@SecurityWeek
8 Jul 2026
1970 Impressions
2 Retweets
11 Likes
2 Bookmarks
0 Replies
0 Quotes
米国CISA¹の既知の悪用された脆弱性カタログに3件と1件の追加。JoomShaper SP Page BuilderのCVE-2026-48908、LangflowのCVE-2026-55255、Joomlack Page BuilderのCVE-2026-56290とColdfusionのCVE-2026-48282。対処期限は3日。ランサム悪用不知。
@__kokumoto
7 Jul 2026
750 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
ColdFusion公開系は棚卸し対象だ。CVE-2026-48282はCVSS 10.0、認証なしRCE、2025 Update 9/2023 Update 20以前が対象。KEVIntelは公開から2時間以内の実悪用をhoneypotで捕捉している。
@connect24h
7 Jul 2026
317 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-48282: CVSS 10.0 path traversal in Adobe ColdFusion RDS FILEIO enables unauthenticated RCE via a single HTTP POST. Actively exploited in the wild and added to CISA KEV. - CVE-2026-48282 (CVSS 10.0) hits the RDS FILEIO handler at POST /CFIDE/main/ide[.]cfm?ACTION=FILEIO.
@DFIR_Radar
6 Jul 2026
176 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Adobe ColdFusion flaw CVE-2026-48282 is now being exploited in the wild Attackers are exploiting a maximum-severity ColdFusion path traversal vulnerability that can lead to remote code execution on unpatched servers. The flaw affects ColdFusion 2025 Update 9 and earlier, a
@DarkWebInformer
6 Jul 2026
14179 Impressions
5 Retweets
50 Likes
12 Bookmarks
3 Replies
0 Quotes
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild: Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a… https://t.co/pNcT6OEsW9 http
@shah_sheikh
6 Jul 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited — attackers hit honeypots within 2 hours of disclosure. ~800 exposed instances online. Patch to ColdFusion 2025 Update 10 or 2023 Update 21 immediately. #CyberSecurity #InfoSec https://t.co/qEAHWbXzUa
@herodevs
6 Jul 2026
219 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Adobe ColdFusion alert: CVE-2026-48282 is now being exploited. It’s a CVSS 10.0 RCE affecting unpatched ColdFusion 2025/2023 installs. Patch now. Check logs. Don’t wait. https://t.co/zle9AaxC5Z #CyberSecurity #InfoSec #ColdFusion #CVE #RCE https://t.co/j4CqOLkbVH
@CyberSecTP
6 Jul 2026
1 Impression
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 ColdFusion admins: this is not a drill. CVE-2026-48282 is a max-severity Adobe ColdFusion RCE now reported exploited in attacks. Affected: CF 2025 U9 & earlier / CF 2023 U20 & earlier. Fix: U10 / U21. Patch now. Lock it down. Hunt. #InfoSec #CyberSecurity #Adobe
@CyberAlliance26
6 Jul 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 06, 2026 1️⃣ CRITICAL ADOBE COLDFUSION FLAW (CVSS 10.0) NOW BEING ACTIVELY EXPLOITED A maximum-severity path traversal vulnerability, CVE-2026-48282, has been discovered in Adobe ColdFusion affecting versions 20
@TraffAlex
6 Jul 2026
287 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Adobe ColdFusion'da kritik RCE açığı (CVE-2026-48282) CVSS: 10.0 Path Traversal zafiyeti nedeniyle saldırganlar, kullanıcı etkileşimi gerektirmeden (UI) uzaktan özel hazırlanmış isteklerle etkilenen ColdFusion sunucularında uygulamanın çalıştığı kullan
@ridvanyagli
3 Jul 2026
228 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Adobe ColdFusionの重大な任意コード実行脆弱性CVE-2026-48282が実際に悪用されている。パストラバーサルの不備により、利用者操作なしで遠隔からサーバーを乗っ取られる恐れがあり、緊急パッチ適用が求められて
@yousukezan
3 Jul 2026
1874 Impressions
2 Retweets
11 Likes
2 Bookmarks
0 Replies
0 Quotes
AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されて
@__kokumoto
1 Jul 2026
759 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
1 Quote
Adobe ColdfusionでCVSSスコア10の脆弱性6件が修正。6/30に11件の脆弱性が修正されたうちの一部。無制限のファイルアップロードCVE-2026-48276及びCVE-2026-48283、入力検証不備CVE-2026-48277、CVE-2026-48281、CVE-2026-48316、パスト
@__kokumoto
30 Jun 2026
764 Impressions
1 Retweet
5 Likes
1 Bookmark
0 Replies
0 Quotes
ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion
@AretiqAI
30 Jun 2026
621 Impressions
1 Retweet
11 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*",
"matchCriteriaId": "B02A37FE-5D31-4892-A3E6-156A8FE62D28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*",
"matchCriteriaId": "0AA3D302-CFEE-4DFD-AB92-F53C87721BFF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*",
"matchCriteriaId": "645D1B5F-2DAB-4AB8-A465-AC37FF494F95",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*",
"matchCriteriaId": "ED6D8996-0770-4C9F-BEA5-87EA479D40A5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*",
"matchCriteriaId": "4836086E-3D4A-4A07-A372-382D385CB490",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*",
"matchCriteriaId": "CBC19168-4184-4B59-B9C8-E98844124EED",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*",
"matchCriteriaId": "A60DCD92-9A5B-411C-9554-642C91D77FAE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*",
"matchCriteriaId": "58CC65EF-60A3-4DFA-AA51-E5013F116CEA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*",
"matchCriteriaId": "2E3EBFB1-4488-4924-A2E2-B7E422D68345",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*",
"matchCriteriaId": "A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*",
"matchCriteriaId": "8689F35F-9A81-45D2-B782-DBA12306BA45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*",
"matchCriteriaId": "5FAA5985-4B25-46C5-8064-0713AB251704",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*",
"matchCriteriaId": "EB88D4FE-5496-4639-BAF2-9F29F24ABF29",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*",
"matchCriteriaId": "9E3884AF-7A1A-4604-B653-6694B7BD1E86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*",
"matchCriteriaId": "43E0ED98-2C1F-40B8-AF60-FEB1D85619C0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*",
"matchCriteriaId": "76204873-C6E0-4202-8A03-0773270F1802",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*",
"matchCriteriaId": "C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*",
"matchCriteriaId": "E3A83642-BF14-4C37-BD94-FA76AABE8ADC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*",
"matchCriteriaId": "A892E1DC-F2C8-4F53-8580-A2D1BEED5A25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*",
"matchCriteriaId": "DB97ADBA-C1A9-4EE0-9509-68CB12358AE5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*",
"matchCriteriaId": "E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*",
"matchCriteriaId": "30779417-D4E5-4A01-BE0E-1CE1D134292A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*",
"matchCriteriaId": "80D7FC6A-F264-4CB1-A18D-B091EBA47882",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*",
"matchCriteriaId": "E3DA0D20-93BA-4C76-A400-159853CD7277",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*",
"matchCriteriaId": "5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*",
"matchCriteriaId": "C85288B9-5D63-49EA-828A-8DB3BB2367F6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*",
"matchCriteriaId": "3882A011-5A01-48E7-B5E7-5A837B1CE245",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*",
"matchCriteriaId": "AACCE621-3380-4144-BA1B-AA26FE96B902",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*",
"matchCriteriaId": "EBC62370-3FA2-4AF7-A201-4155D09051F3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*",
"matchCriteriaId": "D7616F34-9422-4815-806F-4484F68ED2A8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*",
"matchCriteriaId": "FB078BC9-164F-46D0-99F8-086F93FF2046",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]