• News/
  • bleepingcomputer-20260708071655

CISA orders feds to patch max severity ColdFusion flaw by Friday

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 8, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. The vulnerability (CVE-2026-48282) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems. Adobe released security updates one week ago to address the security flaw and urged admins to deploy patches immediately, saying that it posed a high risk of exploitation. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform," the company said. "Adobe recommends administrators install the update as soon as possible. (for example, within 72 hours)." KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS) encouraged network defenders to secure their systems against these ongoing attacks. Internet security watchdog group Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw. On Tuesday, CISA added CVE-2026-4828...

Read full article

Affected Software

1 affected component
Adobe ColdFusion=2025.9, =2023.20, <earlier than 2023.20

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical security vulnerability in Adobe ColdFusion that government agencies are required to patch.

2

What security implications are discussed in the article?

The article highlights that the flaw is actively exploited, posing significant risks to affected systems.

3

What is the specific vulnerability identified in ColdFusion?

The vulnerability is identified as CVE-2026-48282 and is classified as maximum severity.

4

Which versions of ColdFusion are affected by this security flaw?

The flaw affects Adobe ColdFusion versions 2025.9 and 2023.

5

What action has CISA mandated regarding this vulnerability?

CISA has mandated that federal agencies must patch the vulnerability by the upcoming Friday.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203