CVE-2026-48282 is a critical CVSS 10.0 path traversal vulnerability in Adobe ColdFusion allowing remote code execution. Patch immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2023 | 2023 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
| coldfusion | 2025 | 2025 | vulnerable |
Consult Adobe Security Bulletin APSB26-68 and apply the recommended security updates immediately to address the path traversal flaw.
Ensure all Adobe ColdFusion installations are updated beyond versions 2025.9 and 2023.20, as these and all preceding versions are susceptible to remote exploitation.
Implement strict IP whitelisting for ColdFusion administrator interfaces and use a Web Application Firewall (WAF) to block common path traversal patterns like '../' and its encoded variants.
Conduct a forensic audit of web server logs for suspicious directory traversal attempts and unauthorized file uploads or process executions in the ColdFusion service context.
"Monitor web server logs for HTTP requests containing directory traversal sequences such as '../', '..%2f', or '..%5c' targeting ColdFusion endpoints. Watch for unusual child processes spawned by the ColdFusion service, particularly shells like 'cmd.exe' or '/bin/sh'. Additionally, check for unauthorized access to internal configuration files or the creation of unexpected files in web-accessible directories, which may indicate a successful compromise."
Experience superior visibility and a simpler approach to cyber risk management