Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Adobe released security updates on Tuesday to address the vulnerability, saying that it posed a high risk of exploitation and urging admins to deploy patches immediately. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform," Adobe noted. "Adobe recommends administrators install the update as soon as possible (for example, within 72 hours)." Two days later, KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting CVE-2026-48282 within two hours of Adobe's disclosure. "Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network," Dewhurst said. The Canadian Center for Cyber Security (CCCS), the Government of Canada authority that coordinates the country's national response to cybersecurity incidents, also urged defenders to secure their systems against ongoing attacks. "Open-source reportin...
Max severity Adobe ColdFusion flaw now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Adobe ColdFusion>=2023.20<=2025.9, <=2023.20
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a critical Adobe ColdFusion vulnerability tracked as CVE-2026-48282.
2
What security implications are discussed?
The article highlights that the flaw is being actively exploited in attacks, posing significant risks to applications using ColdFusion.
3
What products or software are affected?
The vulnerability specifically affects Adobe ColdFusion, a web application development platform.
4
Who reported the active exploitation of this vulnerability?
The active exploitation of CVE-2026-48282 was reported by vulnerability intelligence company KEVIntel.
5
When was the vulnerability published and modified?
The vulnerability was published and modified on July 6, 2026.