cbcvebase.
CVE-2026-48282
published 2026-06-30

CVE-2026-48282: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability…

PriorityP197critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-10
Exploited in the wild
EPSS
42.39%
98.7th percentile
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion
adobecoldfusion

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier) that can lead to arbitrary code execution without user interaction; monitor ColdFusion servers for anomalous path traversal patterns in HTTP requests (e.g., directory traversal sequences in request URIs)
  • Scope is changed per CVE scoring, indicating the vulnerability can impact components beyond the vulnerable ColdFusion instance itself; treat any successful exploitation as a potential pivot point and investigate lateral movement
  • Adobe ColdFusion is actively exploited in the wild per CISA KEV; apply forensic triage per BOD 26-04 requirements on any exposed ColdFusion instance and review for indicators of compromise before patching
  • ·Remediation deadline is 2026-07-10 per CISA KEV for affected federal and BOD-scoped organizations

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.