Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A Critical Adobe ColdFusion Vulnerability Has Been Exploited in Attacks, Despite Being Recently Patched

Threat actors have begun exploiting a critical vulnerability in Adobe’s ColdFusion platform, despite it being patched just two weeks ago. The flaw, tracked as CVE-2026-48282, is described as a path traversal that could lead to arbitrary code execution and has been assigned a maximum severity rating of 10 out of 10 by the vendor.

Adobe released patches for six high-severity vulnerabilities in ColdFusion on June 30, including the one now being exploited. The company urged users to apply the patches as soon as possible, given the high risk that attackers could start targeting the flaws. However, it appears that hackers have already begun exploiting CVE-2026-48282, with reports emerging of attacks taking place within just two hours of its public disclosure.

According to vulnerability intelligence platform KEVIntel, the company’s global honeypot network detected in-the-wild exploitation of the flaw shortly after its public disclosure. This is a concerning development, as it highlights the rapid pace at which attackers are now able to exploit newly disclosed vulnerabilities.

The Canadian Centre for Cyber Security has also warned that CVE-2026-48282 has been exploited in attacks, based on open-source reporting. Adobe’s advisory still does not mention the vulnerability’s in-the-wild exploitation, but the company has been notified and will update its guidance as necessary.

Experts are sounding the alarm about the speed at which attackers can now exploit vulnerabilities. “The challenge is determining which systems are reachable, which vulnerabilities create attack paths, and what compensating controls can reduce exposure while remediation is underway,” said Piyush Sharma, co-founder and CEO of Tuskira. “As the window between disclosure and exploitation continues to shrink, organizations will increasingly compete on the speed and quality of their security decisions.”

This incident serves as a stark reminder that patching vulnerabilities is not enough; users must also prioritize validating, testing, and deploying patches across production environments in a timely manner.

For those using Adobe ColdFusion, it’s essential to apply the latest patches and stay vigilant. This includes ensuring that all systems are reachable, identifying potential attack paths, and implementing compensating controls to reduce exposure while remediation is underway. By taking proactive steps to secure their environment, organizations can minimize the risk of falling victim to attacks exploiting this critical vulnerability.


Source: SecurityWeek — 2026-07-07