CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive to federal agencies, ordering them to patch a critical vulnerability in Adobe ColdFusion by Friday. The move comes as threat actors have been actively exploiting this maximum-severity flaw, which can be used to gain code execution on unpatched systems with minimal complexity.

The vulnerability, identified as CVE-2026-48282, affects ColdFusion versions 2025.9 and earlier, including the latest version, 2023.20. It’s a classic example of a remotely exploitable flaw that can be used by attackers to gain unauthorized access to sensitive systems. Adobe first warned about this vulnerability last week, urging administrators to deploy patches as soon as possible.

What’s alarming is that threat actors have already begun exploiting this flaw in the wild, with reports suggesting that they started within hours of Adobe’s disclosure. This highlights the urgent need for agencies and organizations to prioritize patching, especially when vulnerabilities are being actively exploited.

CISA has added CVE-2026-48282 to its list of vulnerabilities actively exploited in attacks, which is a clear indication of the severity of this issue. The agency has ordered federal civilian executive branch (FCEB) agencies to patch their systems by Friday as part of its Binding Operational Directive (BOD) 26-04.

This directive requires federal agencies to prioritize patching based on several factors, including whether flaws are included in CISA’s KEV catalog, the ease of exploitation, and the potential impact on vulnerable assets. It’s a timely reminder that patching is not just about applying security updates; it’s also about protecting against the very real threat of cyber attacks.

What’s also notable is that this vulnerability is just one of several maximum-severity flaws in Adobe ColdFusion that have been patched recently. Last week, the company released fixes for six other critical vulnerabilities in its web app development and marketing automation platforms. However, it’s clear that these patches are not a one-time fix; organizations need to remain vigilant and keep their systems up-to-date with the latest security updates.

For those affected by this vulnerability, it’s essential to take immediate action. Patching is no longer just an optional security measure but a mandatory requirement for protecting against the very real threat of cyber attacks. Organizations should review their patch management processes to ensure that they are keeping pace with the rapidly evolving threat landscape.

In conclusion, the urgent directive from CISA serves as a stark reminder of the importance of prioritizing patching and staying ahead of the threat actors. As security teams, it’s essential to test every layer before attackers do, using breach and attack simulation tests to validate our detection and response capabilities. By doing so, we can ensure that threats are stopped in their tracks and don’t slip through our defenses unnoticed.


Source: Bleeping Computer — 2026-07-08