• News/
  • bleepingcomputer-20260706131837

Max severity Adobe ColdFusion flaw now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 6, 2026
·
Updated

Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Adobe released security updates on Tuesday to address the vulnerability, saying that it posed a high risk of exploitation and urging admins to deploy patches immediately. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform," Adobe noted. "Adobe recommends administrators install the update as soon as possible (for example, within 72 hours)." Two days later, KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting CVE-2026-48282 within two hours of Adobe's disclosure. "Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network," Dewhurst said. The Canadian Center for Cyber Security (CCCS), the Government of Canada authority that coordinates the country's national response to cybersecurity incidents, also urged defenders to secure their systems against ongoing attacks. "Open-source reportin...

Read full article

Affected Software

1 affected component
Adobe ColdFusion>=2023.20<=2025.9, <=2023.20

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical Adobe ColdFusion vulnerability tracked as CVE-2026-48282.

2

What security implications are discussed?

The article highlights that the flaw is being actively exploited in attacks, posing significant risks to applications using ColdFusion.

3

What products or software are affected?

The vulnerability specifically affects Adobe ColdFusion, a web application development platform.

4

Who reported the active exploitation of this vulnerability?

The active exploitation of CVE-2026-48282 was reported by vulnerability intelligence company KEVIntel.

5

When was the vulnerability published and modified?

The vulnerability was published and modified on July 6, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203