All stories
criticalExploited VulnerabilitiesCVE-2026-48282

Attackers exploit critical path traversal vulnerabilities in Adobe ColdFusion for remote code execution

Critical path traversal flaws in Adobe ColdFusion are being actively exploited to achieve remote code execution. Attackers began targeting these systems within two hours of the vulnerability's public disclosure. Administrators must update ColdFusion to the latest versions immediately to prevent unauthorized access.

Summary

A maximum-severity vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, is currently being exploited in the wild. The flaw allows unauthenticated attackers to execute arbitrary code on vulnerable systems without any user interaction.

Exploitation began almost immediately following the disclosure of technical details. KEVIntel reported capturing in-the-wild exploitation within two hours of the public release. This rapid timeline underscores the urgency for organizations running ColdFusion to apply available security updates.

Technical details

The vulnerability, assigned a CVSS score of 10.0, stems from an Improper Limitation of a Pathname to a Restricted Directory, commonly known as a path traversal flaw. This weakness allows an attacker to navigate outside intended directories to access restricted files or execute commands.

Successful exploitation results in arbitrary code execution within the context of the current user running the ColdFusion service. Because the attack requires no privileges and no user interaction, it poses a critical risk to any exposed web application development platform.

Affected products and fixed versions

The vulnerability impacts several versions of Adobe's enterprise-grade web development tools.

Product Affected Versions
Adobe ColdFusion 2025 2025.9 and earlier
Adobe ColdFusion 2023 2023.20 and earlier

Adobe also recently released patches for six maximum-severity flaws affecting ColdFusion and Campaign Classic, though specific exploitation details for those additional flaws were not confirmed in the same manner as CVE-2026-48282.

Exploitation status

The vulnerability is actively being exploited. While Adobe initially stated they were not aware of any exploits in the wild at the time of their update release, subsequent intelligence from KEVIntel confirmed that threat actors began targeting the flaw within two hours of the details becoming public.

The Canadian Center for Cyber Security (CCCS) has also issued alerts confirming that open-source reporting indicates active exploitation of CVE-2026-48282. Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, though it is unclear how many of these are vulnerable or have already been compromised.

Defender guidance

Administrators should prioritize the following actions to mitigate risk:

  • Apply Security Updates: Install the latest patches for ColdFusion immediately. Adobe recommends deploying updates within 72 hours of release due to the high risk of targeting.
  • Verify Versions: Ensure your environment is running ColdFusion 2025 Update 9 or later, or ColdFusion 2023 Update 20 or later.
  • Monitor for Path Traversal Patterns: Audit web server logs for unusual directory traversal attempts (e.g., ../ sequences) targeting the ColdFusion installation directory.

Sources

  1. https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/
  2. https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
  3. http://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-647
  4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=All&url=&f%5B0%5D=vendor_project%3A791
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -