CVE-2026-48282
published 2026-06-30CVE-2026-48282: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability…
PriorityP197critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-10
Exploited in the wild
EPSS
42.39%
98.7th percentile
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
| adobe | coldfusion | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier) that can lead to arbitrary code execution without user interaction; monitor ColdFusion servers for anomalous path traversal patterns in HTTP requests (e.g., directory traversal sequences in request URIs) ↗
- →Scope is changed per CVE scoring, indicating the vulnerability can impact components beyond the vulnerable ColdFusion instance itself; treat any successful exploitation as a potential pivot point and investigate lateral movement ↗
- →Adobe ColdFusion is actively exploited in the wild per CISA KEV; apply forensic triage per BOD 26-04 requirements on any exposed ColdFusion instance and review for indicators of compromise before patching ↗
- ·Remediation deadline is 2026-07-10 per CISA KEV for affected federal and BOD-scoped organizations ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut
ghsa_unreviewed·2026-06-30
CVE-2026-48282 [CRITICAL] CWE-22 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
VulDB
Adobe ColdFusion up to 2023.20/2025.9 path traversal (apsb26-68)
vuldb·2026-06-30·CVSS 10.0
CVE-2026-48282 [CRITICAL] Adobe ColdFusion up to 2023.20/2025.9 path traversal (apsb26-68)
A vulnerability was found in Adobe ColdFusion up to 2023.20/2025.9. It has been classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-48282. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
VulnCheck
Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2026·CVSS 9.3
CVE-2026-48313 [CRITICAL] Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Affected: Adobe ColdFusion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.crowdsec.net/vulntracking-report/cve-2026-4828
VulnCheck
Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2026·CVSS 10.0
CVE-2026-48282 [CRITICAL] Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Affected: Adobe ColdFusion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-48282; https://www.linkedin.com/posts/ryandewhurst_within-under-two-hours-of-cve-2026-48282-share-7478514643582418944-2-c5/
CISA
Adobe ColdFusion Path Traversal Vulnerability
cisa·2026-07-07·CVSS 10.0
CVE-2026-48282 [CRITICAL] CWE-22 Adobe ColdFusion Path Traversal Vulnerability
Vulnerability: Adobe ColdFusion Path Traversal Vulnerability
Affected: Adobe ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://helpx.adobe.com/security/products/coldfusion/apsb26
No detection rules found.
Nuclei
Adobe ColdFusion - RDS Arbitrary File Write
nuclei·CVSS 10.0
CVE-2026-48282 [CRITICAL] Adobe ColdFusion - RDS Arbitrary File Write
Adobe ColdFusion - RDS Arbitrary File Write
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. The RDS FILEIO WRITE operation allows unauthenticated attackers to write arbitrary files when RDS is enabled with authentication disabled. Exploitation of this issue does not require user interaction. Scope is changed.
Template:
id: CVE-2026-48282
info:
name: Adobe ColdFusion - RDS Arbitrary File Write
author: watchtowr,DhiyaneshDk
severity: critical
description: |
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'
Hackernews
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
blogs_hackernews·2026-07-08·CVSS 10.0
CVE-2026-48282 [CRITICAL] CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user.
CVE-2026-56290 (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unaut
Hackernews
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
blogs_hackernews·2026-07-06
CVE-2026-48276 ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary.
Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throughout: trust placed one layer too early.
Below is the full recap, since this is apparently what counted as a normal week.
## ⚡ Threat of the Week
Net
Hackernews
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
blogs_hackernews·2026-07-01·CVSS 10.0
CVE-2026-48276 [CRITICAL] Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic.
The ColdFusion updates "resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass," Adobe said in an alert released Tuesday.
The vulnerabilities are listed below -
CVE-2026-48276, CVE-2026-48283 (CVSS scores: 10.0) - Unrestricted upload of file with dangerous type vulnerabilities that could lead to arbitrary code executio
2026-06-30
Published
2026-07-07
Added to CISA KEV
Exploited in the wild