CVE-2026-48282: ColdFusion Path Traversal vulnerability exploited hours after disclosure

Last Updated: 2026-07-09T01:35:03Z

What’s Happening

ColdFusion 2023 (update 20 and earlier) and 2025 (update 9) is vulnerable to path traversal, as notated in CVE-2026-48282. While not immediately thought to be exploited in the wild, later evidence showed that exploitation began hours after disclosure.

Actions

Patch ColdFusion with 2023 (update 21) or 2025 (update 10).

Notes

The vulnerability was given a priority rating but didn’t get strong uptake. It was reported by Adobe that no live exploitation was known, which may have slowed adoption. However, the Canadian Cyber Security Center declared known attacks on July 2, and then CISA included the exploits on July 7.