CVE-2026-48282
CISA KEVAs of 2026-07-08, CVE-2026-48282 is a CVSS 10 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 28.6%. Threadlinqs Intelligence tracks 5 threats exploiting it.
Last updated: 2026-07-08
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-22
Exploitation status
CISA KEV-listed (known exploited) · public exploit code available · nuclei detection template exists
Threats tracking this CVE
- Adobe ColdFusion Critical Path Traversal in RDS FILEIO Handler Enables Unauthenticated RCE (CVE-2026-48282) — CRITICAL
- Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69) — CRITICAL
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution — CRITICAL
- Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69) — CRITICAL
- Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286) — CRITICAL
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.