The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. The vulnerability (CVE-2026-48282) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems. Adobe released security updates one week ago to address the security flaw and urged admins to deploy patches immediately, saying that it posed a high risk of exploitation. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform," the company said. "Adobe recommends administrators install the update as soon as possible. (for example, within 72 hours)." KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS) encouraged network defenders to secure their systems against these ongoing attacks. Internet security watchdog group Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw. On Tuesday, CISA added CVE-2026-4828...
CISA orders feds to patch max severity ColdFusion flaw by Friday
BleepingComputer
·Sergiu Gatlan
·Published Jul 8, 2026
·Updated
Affected Software
1 affected component
Adobe ColdFusion=2025.9, =2023.20, <earlier than 2023.20
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical security vulnerability in Adobe ColdFusion that government agencies are required to patch.
2
What security implications are discussed in the article?
The article highlights that the flaw is actively exploited, posing significant risks to affected systems.
3
What is the specific vulnerability identified in ColdFusion?
The vulnerability is identified as CVE-2026-48282 and is classified as maximum severity.
4
Which versions of ColdFusion are affected by this security flaw?
The flaw affects Adobe ColdFusion versions 2025.9 and 2023.
5
What action has CISA mandated regarding this vulnerability?
CISA has mandated that federal agencies must patch the vulnerability by the upcoming Friday.