Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48282

Published 2026-06-30
Updated 24 days ago
Vendor/s
Adobe
Product/s
ColdFusion
Version/s
2023
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-48282 is a critical CVSS 10.0 path traversal vulnerability in Adobe ColdFusion allowing remote code execution. Patch immediately.

CPE

Adobe logo
Adobe
Product Version Start Version End (excl.) Status
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2023 2023 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable
coldfusion 2025 2025 vulnerable

Related weakness (CWE)

CWE-22

Remediation plan

1

Apply official patches

Consult Adobe Security Bulletin APSB26-68 and apply the recommended security updates immediately to address the path traversal flaw.

2

Update affected systems

Ensure all Adobe ColdFusion installations are updated beyond versions 2025.9 and 2023.20, as these and all preceding versions are susceptible to remote exploitation.

3

Restrict access

Implement strict IP whitelisting for ColdFusion administrator interfaces and use a Web Application Firewall (WAF) to block common path traversal patterns like '../' and its encoded variants.

4

Monitor for exploitation

Conduct a forensic audit of web server logs for suspicious directory traversal attempts and unauthorized file uploads or process executions in the ColdFusion service context.

Detection Guidance

"Monitor web server logs for HTTP requests containing directory traversal sequences such as '../', '..%2f', or '..%5c' targeting ColdFusion endpoints. Watch for unusual child processes spawned by the ColdFusion service, particularly shells like 'cmd.exe' or '/bin/sh'. Additionally, check for unauthorized access to internal configuration files or the creation of unexpected files in web-accessible directories, which may indicate a successful compromise."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management