Path Traversal Vulnerability in Adobe ColdFusion Products
CVE-2026-48282

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

Badges

📈 Trended📈 Score: 4,780💰 Ransomware👾 Exploit Exists🟣 EPSS 28%🦅 CISA Reported📰 News Worthy

What is CVE-2026-48282?

CVE-2026-48282 is a significant vulnerability identified in Adobe ColdFusion products, specifically impacting versions 2025.9, 2023.20, and earlier. ColdFusion is a commercial rapid web application development platform that allows developers to create and deploy dynamic websites and applications. This particular vulnerability stems from an improper management of pathnames, commonly referred to as a Path Traversal vulnerability. Attackers can exploit this flaw to potentially execute arbitrary code within the context of the user currently running the application. Unlike many other vulnerabilities, exploitation of CVE-2026-48282 does not require any user interaction, making it particularly dangerous for organizations. If left unaddressed, this vulnerability could allow malicious actors to manipulate the application, access sensitive data, or impact overall application functionality adversely.

Potential impact of CVE-2026-48282

  1. Arbitrary Code Execution: The most critical impact is the potential for attackers to execute arbitrary code on the server. This could result in unauthorized access to the system, allowing attackers to control and manipulate the server according to their objectives.

  2. Data Breaches: Given the nature of the ColdFusion platform, which often handles sensitive information, successful exploitation of this vulnerability could lead to unauthorized access to confidential data. This breach could have severe implications for data privacy and security compliance.

  3. Operational Disruption: Exploiting this vulnerability could lead to operational disruptions within an organization. If attackers gain control of the application, they could disrupt services, leading to downtime, loss of revenue, and damage to the organization's reputation.

CISA has reported CVE-2026-48282

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-48282 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

ColdFusion 0 <= 2023.20

News Articles

Week in review: Accenture data breach, great open-source cybersecurity tools - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security

1 week ago

CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks - IT Security News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in real-world attacks. The issue stems from…Read mo...

2 weeks ago

CISA Warns of Actively Exploited Adobe ColdFusion Vulnerability - IT Security News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited in the wild. Disclosed on July 7, 2026,…Read more →

2 weeks ago

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 💰

    Used in Ransomware

  • 📈

    Vulnerability started trending

  • 🦅

    CISA Reported

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.