The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to all federal government agencies in the United States: they must patch an extremely critical vulnerability in the Adobe ColdFusion web application development platform by this Friday. The flaw, identified as CVE-2026-48282, is being actively exploited by malicious actors, and CISA has labeled it as a maximum-severity threat.
Adobe first released patches for this vulnerability just over a week ago, urging administrators to deploy them immediately due to the high risk of exploitation. However, since then, reports have emerged that attackers have already begun exploiting the flaw in the wild, with some estimates suggesting that nearly 800 instances of Adobe ColdFusion are exposed online.
The vulnerability affects versions 2025.9 and earlier of the platform, allowing remote threat actors to execute code on unpatched systems without even needing administrative privileges. This is particularly concerning, as it indicates a high complexity attack vector that can be easily exploited by attackers.
CISA has added CVE-2026-48282 to its list of vulnerabilities actively exploited in attacks and has ordered federal agencies to prioritize patching based on CISA’s KEV catalog, which takes into account the severity of the flaw, its potential for large-scale automated exploitation, and whether vulnerable assets are exposed online. This directive is part of a broader effort by the US government to ensure that all federal agencies maintain robust cybersecurity defenses.
The inclusion of this vulnerability in CISA’s actively exploited list comes just weeks after Adobe patched six other maximum-severity flaws in ColdFusion, including ones related to Campaign Classic marketing automation platforms. While these patches were also released with high urgency, there is no indication yet that they have been exploited in the wild.
This latest development serves as a stark reminder of the ongoing threat posed by cyber vulnerabilities and the need for prompt patching and maintenance of software applications. As we’ve seen time and again, exploits can spread rapidly once a vulnerability is identified, making it essential for organizations to stay vigilant and proactive in their cybersecurity efforts.
So what can you do to protect yourself? First and foremost, ensure that all Adobe ColdFusion installations are up-to-date with the latest patches. If you’re unsure about the version of your platform or have any questions about patching, consult with your IT team or contact Adobe support for assistance. By staying on top of security updates and taking proactive steps to prevent attacks, you can significantly reduce the risk of falling victim to these types of exploits.
Source: Bleeping Computer — 2026-07-08