/00 — boot sequence

Hello.

Article

Adobe ColdFusion CVE-2026-48282: Max Severity RCE Under Active Exploitation, CISA Orders Patch

July 9, 2026•4 min read
security adobe coldfusion cve vulnerability exploit

A critical remote code execution vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282 with a maximum severity rating, is now being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to patch by Friday. Attackers began exploiting the vulnerability within two hours of Adobes disclosure.

Vulnerability Details

CVE-2026-48282 affects Adobe ColdFusion, a commercial rapid web application development platform widely used in enterprise environments. The vulnerability carries the maximum CVSS severity rating and requires no authentication or user privileges to exploit.

FieldDetails
CVECVE-2026-48282
SeverityMaximum (Critical)
Attack VectorRemote, unauthenticated
ComplexityLow
Privileges RequiredNone
ImpactRemote Code Execution
Affected VersionsColdFusion 2025.9, 2023.20, and earlier
FixAdobe security update released July 2, 2026

Active Exploitation Timeline

The exploitation timeline is alarming: attackers began targeting CVE-2026-48282 within two hours of Adobe releasing its security bulletin. Threat actors moved at unprecedented speed, suggesting either reverse-engineering of the patch or independent discovery of the vulnerability.

CISA has added CVE-2026-48282 to its KEV catalog and mandated that U.S. Federal Civilian Executive Branch (FCEB) agencies patch by Friday under Binding Operational Directive (BOD) 26-04. The Canadian Center for Cyber Security (CCCS) has also encouraged network defenders to secure their systems.

Internet security watchdog Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, though it is unclear how many have been patched.

Impact Assessment

This vulnerability is significant for several reasons:

No Authentication Required. Remote attackers can exploit this flaw without any credentials or user interaction, making mass exploitation straightforward.

Low Complexity. The attack is classified as low-complexity, meaning it does not require specialized conditions or advanced techniques.

Full Remote Code Execution. Successful exploitation gives attackers the ability to execute arbitrary code on the target server, potentially leading to full server compromise, data theft, lateral movement, and ransomware deployment.

Widespread Enterprise Use. ColdFusion is deployed across government agencies, financial institutions, healthcare organizations, and large enterprises, many of which may have exposed instances.

Affected Systems

Any organization running Adobe ColdFusion version 2025.9, 2023.20, or earlier is at risk. The vulnerability is remotely exploitable, so even systems behind a firewall may be vulnerable if ColdFusion is exposed to the internet.

This is the second major ColdFusion incident in 2026. In April, Adobe released emergency patches for an Acrobat Reader zero-day (CVE-2026-34621). Since November 2021, CISA has added 80 vulnerabilities in Adobe products to its KEV catalog, 10 of which have been abused in ransomware attacks.

Adobe also patched six other maximum-severity flaws in ColdFusion and the Campaign Classic marketing automation platform in the same update, though none have been confirmed as exploited in the wild.

Mitigation and Patching

Adobe released security updates on July 2, 2026 addressing CVE-2026-48282. The company strongly recommended administrators install updates within 72 hours given the high risk of exploitation.

Steps to protect your systems:

  1. Identify all ColdFusion instances in your environment
  2. Update to the latest patched versions immediately
  3. If immediate patching is not possible, restrict network access to ColdFusion servers
  4. Monitor for signs of exploitation (unexpected file creation, unusual process execution)
  5. Review Shadowserver internet-exposed instance tracking for your organization

Check your ColdFusion version:

  • Log into the ColdFusion Administrator console
  • Navigate to the System Information page
  • Verify the version is patched beyond 2025.9 or 2023.20

Detection

Signs of CVE-2026-48282 exploitation may include:

  • Unexpected system commands executed from the ColdFusion process
  • Unusual files written to web-accessible directories
  • Outbound connections from the ColdFusion server to unknown IPs
  • Web server logs showing anomalous POST requests to ColdFusion endpoints

Security teams should prioritize reviewing ColdFusion access logs and monitoring for post-exploitation activity.

Frequently Asked Questions

Does this vulnerability require authentication?

No. CVE-2026-48282 can be exploited remotely without any authentication or user interaction.

Which ColdFusion versions are affected?

ColdFusion 2025.9, 2023.20, and all earlier versions. Adobe has released patches for both release lines.

Has this been exploited in the wild?

Yes. Attackers began exploiting CVE-2026-48282 within two hours of Adobes security disclosure. CISA has confirmed active exploitation.

Is there a workaround if I cannot patch immediately?

Restrict network access to ColdFusion servers to trusted IPs only. Consider placing ColdFusion instances behind a VPN or WAF until patches can be applied.

How many ColdFusion instances are exposed?

Shadowserver tracks approximately 800 internet-exposed ColdFusion instances globally.

Key Takeaways

  • CVE-2026-48282 is a maximum-severity, unauthenticated RCE in Adobe ColdFusion
  • Exploitation began within 2 hours of Adobes disclosure
  • CISA has added it to KEV and ordered federal agencies to patch by Friday
  • Affects ColdFusion 2025.9, 2023.20, and earlier versions
  • Approximately 800 instances remain exposed online
  • Adobe also patched 6 other max-severity flaws in the same update

Conclusion

CVE-2026-48282 is a textbook example of how quickly threat actors move once a vulnerability is disclosed. With exploitation starting within two hours and a public CISA KEV entry, this is not a vulnerability that can wait for the next patch cycle. If your organization uses ColdFusion, patch today, not tomorrow.


Sources: BleepingComputer, Security Affairs, CISA KEV Catalog

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links