CVE-2026-48282

Published Jun 30, 2026

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48282 is identified as a path traversal vulnerability affecting Adobe ColdFusion versions 2025.9, 2023.20, and earlier releases. This flaw, categorized as an Improper Limitation of a Pathname to a Restricted Directory (CWE-22), allows an attacker to execute arbitrary code in the context of the current user. Exploitation of CVE-2026-48282 does not require user interaction or any specific privileges, making it accessible over a network by sending crafted HTTP requests to a ColdFusion endpoint. Attackers can manipulate file system paths using traversal sequences to access or write files outside of the intended restricted directory, which can then be chained to achieve arbitrary code execution. This vulnerability has been observed under active exploitation shortly after its public disclosure.

Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Source
psirt@adobe.com
NVD status
Analyzed
Products
coldfusion

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe ColdFusion Path Traversal Vulnerability
Exploit added on
Jul 7, 2026
Exploit action due
Jul 10, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@adobe.com
CWE-22

Social media

Hype score
Not currently trending
  1. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is exploited in the wild. Patched June 30 (APSB26-68); added to CISA KEV July 7. Unauthenticated RCE where RDS is enabled with auth disabled. Affected: 2025 ≤Update 9, 2023 ≤Update 20; fixed in Update 10/21.

    @InfosecDotWatch

    13 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-48282 ❗ CVE-2026-48277 ❗ CVE-2026-48276 ➡️ Más info: https://t.co/KWl5pRIS2P https://t.co/OikXx2L4Fk

    @CERTpy

    13 Jul 2026

    221 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⏰ Admins — the CISA KEV deadline was July 10. Did you patch these 4 actively exploited flaws? 🔹 CVE-2026-48282 — Adobe ColdFusion path traversal → code execution 🔹 CVE-2026-56290 — Joomlack Page Builder unauthenticated upload → RCE 🔹 CVE-2026-55255 — Langf

    @techepages

    13 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...

    @Joe_Biden_ja

    11 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. AdobeのWebアプリケーションサーバー「ColdFusion」のCVE-2026-48282は、6月30日の修正公開からわずか2日後にCCCS(カナダサイバーセキュリティセンター)が実環境での悪用報告を警告し、7月7日にはCISAもKEV(悪用確認

    @MalwareBibleJP

    10 Jul 2026

    1431 Impressions

    0 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. 800+ ColdFusion servers exposed. CVE-2026-48282 (CVSS 10.0) exploited within 2 hours of disclosure. CISA patch deadline is TODAY. Patch to 2025 Update 10 or disable RDS now. https://t.co/hi6Gy04edk #ColdFusion #CVE202648282 #CISAKOV #PatchNow #CyberSecurity https://t.co/ElrS5Jelj

    @DecryptionDigst

    10 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(7/7追加) 🛡CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Adobe Systems Incorporated (CNA) ・種別:パス・ト

    @piyokango

    8 Jul 2026

    5796 Impressions

    0 Retweets

    9 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  8. After analyzing 28% of vulnerabilities from past week, CVE-2026-48282 has 19 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    8 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-48282: Unauthenticated path traversal in Adobe ColdFusion allows RCE. Affects 2025.x up to 2025.9, 2023.x up to 2023.20. Actively exploited; patches via APSB26-68. Disable RDS if not needed.

    @GreyZoneSec

    8 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 CVE-2026-48282 Adobe ColdFusion, CVSS 10.0 Path traversal dans le RDS (FILEIO) → lecture/écriture de fichiers arbitraires sans auth → RCE. Déjà exploité dans la nature, ajouté au KEV CISA. Patchez : CF 2025 U10 / 2023 U21. Coupez le RDS si pas utilisé. PoC 👇

    @Sn0wAlice

    8 Jul 2026

    249 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. It's Already When. — Field Note Active exploitation of max-severity ColdFusion (CVE-2026-48282), Langflow, and Gitea (CVE-2026-20896) flaws, plus GhostLock (CVE-2026-43499)... https://t.co/89LSZTiW9G #CyberSecurity #BlueTeam

    @itsalreadywhen

    8 Jul 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws - https://t.co/rnuxt9VXQm (CVE-2026-48282, CVE-2026-55255, CVE-2026-33017)

    @SecurityWeek

    8 Jul 2026

    1970 Impressions

    2 Retweets

    11 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  13. 米国CISA¹の既知の悪用された脆弱性カタログに3件と1件の追加。JoomShaper SP Page BuilderのCVE-2026-48908、LangflowのCVE-2026-55255、Joomlack Page BuilderのCVE-2026-56290とColdfusionのCVE-2026-48282。対処期限は3日。ランサム悪用不知。

    @__kokumoto

    7 Jul 2026

    750 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. ColdFusion公開系は棚卸し対象だ。CVE-2026-48282はCVSS 10.0、認証なしRCE、2025 Update 9/2023 Update 20以前が対象。KEVIntelは公開から2時間以内の実悪用をhoneypotで捕捉している。

    @connect24h

    7 Jul 2026

    317 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. CVE-2026-48282: CVSS 10.0 path traversal in Adobe ColdFusion RDS FILEIO enables unauthenticated RCE via a single HTTP POST. Actively exploited in the wild and added to CISA KEV. - CVE-2026-48282 (CVSS 10.0) hits the RDS FILEIO handler at POST /CFIDE/main/ide[.]cfm?ACTION=FILEIO.

    @DFIR_Radar

    6 Jul 2026

    176 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. 🚨 Adobe ColdFusion flaw CVE-2026-48282 is now being exploited in the wild Attackers are exploiting a maximum-severity ColdFusion path traversal vulnerability that can lead to remote code execution on unpatched servers. The flaw affects ColdFusion 2025 Update 9 and earlier, a

    @DarkWebInformer

    6 Jul 2026

    14179 Impressions

    5 Retweets

    50 Likes

    12 Bookmarks

    3 Replies

    0 Quotes

  17. Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild: Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a… https://t.co/pNcT6OEsW9 http

    @shah_sheikh

    6 Jul 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited — attackers hit honeypots within 2 hours of disclosure. ~800 exposed instances online. Patch to ColdFusion 2025 Update 10 or 2023 Update 21 immediately. #CyberSecurity #InfoSec https://t.co/qEAHWbXzUa

    @herodevs

    6 Jul 2026

    219 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Adobe ColdFusion alert: CVE-2026-48282 is now being exploited. It’s a CVSS 10.0 RCE affecting unpatched ColdFusion 2025/2023 installs. Patch now. Check logs. Don’t wait. https://t.co/zle9AaxC5Z #CyberSecurity #InfoSec #ColdFusion #CVE #RCE https://t.co/j4CqOLkbVH

    @CyberSecTP

    6 Jul 2026

    1 Impression

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  20. 🚨 ColdFusion admins: this is not a drill. CVE-2026-48282 is a max-severity Adobe ColdFusion RCE now reported exploited in attacks. Affected: CF 2025 U9 & earlier / CF 2023 U20 & earlier. Fix: U10 / U21. Patch now. Lock it down. Hunt. #InfoSec #CyberSecurity #Adobe

    @CyberAlliance26

    6 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 06, 2026 1️⃣ CRITICAL ADOBE COLDFUSION FLAW (CVSS 10.0) NOW BEING ACTIVELY EXPLOITED A maximum-severity path traversal vulnerability, CVE-2026-48282, has been discovered in Adobe ColdFusion affecting versions 20

    @TraffAlex

    6 Jul 2026

    287 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. 🚨 Adobe ColdFusion'da kritik RCE açığı (CVE-2026-48282) CVSS: 10.0 Path Traversal zafiyeti nedeniyle saldırganlar, kullanıcı etkileşimi gerektirmeden (UI) uzaktan özel hazırlanmış isteklerle etkilenen ColdFusion sunucularında uygulamanın çalıştığı kullan

    @ridvanyagli

    3 Jul 2026

    228 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Adobe ColdFusionの重大な任意コード実行脆弱性CVE-2026-48282が実際に悪用されている。パストラバーサルの不備により、利用者操作なしで遠隔からサーバーを乗っ取られる恐れがあり、緊急パッチ適用が求められて

    @yousukezan

    3 Jul 2026

    1874 Impressions

    2 Retweets

    11 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  24. AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されて

    @__kokumoto

    1 Jul 2026

    759 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    1 Quote

  25. Adobe ColdfusionでCVSSスコア10の脆弱性6件が修正。6/30に11件の脆弱性が修正されたうちの一部。無制限のファイルアップロードCVE-2026-48276及びCVE-2026-48283、入力検証不備CVE-2026-48277、CVE-2026-48281、CVE-2026-48316、パスト

    @__kokumoto

    30 Jun 2026

    764 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  26. ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion

    @AretiqAI

    30 Jun 2026

    621 Impressions

    1 Retweet

    11 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations