Last Updated: 2026-07-09T01:35:03Z
What’s Happening
ColdFusion 2023 (update 20 and earlier) and 2025 (update 9) is vulnerable to path traversal, as notated in CVE-2026-48282. While not immediately thought to be exploited in the wild, later evidence showed that exploitation began hours after disclosure.
- NVD - CVE-2026-48282
- https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
- Critical Adobe ColdFusion Vulnerability Exploited in Attacks - SecurityWeek
Actions
Patch ColdFusion with 2023 (update 21) or 2025 (update 10).
Notes
The vulnerability was given a priority rating but didn’t get strong uptake. It was reported by Adobe that no live exploitation was known, which may have slowed adoption. However, the Canadian Cyber Security Center declared known attacks on July 2, and then CISA included the exploits on July 7.