CVE-2026-48282: critical Adobe ColdFusion vulnerability actively exploited
CVE-2026-48282 alert: critical flaw (CVSS 10) in Adobe ColdFusion, in the CISA KEV catalog. What to do if you use this platform.
CVE-2026-48282: critical Adobe ColdFusion vulnerability actively exploited
In short
A critical vulnerability in Adobe ColdFusion (CVE-2026-48282) has been confirmed, with the maximum severity score, CVSS 10.0 out of 10 [1]. It affects versions 2025.9, 2023.20 and earlier [1], and is included in the catalog of actively exploited vulnerabilities maintained by the US agency CISA (KEV) [2], which means its real-world use by attackers has already been detected. If your company operates servers running Adobe ColdFusion, today's priority is to identify those systems, check the installed version, and apply the vendor's patch as soon as possible.
What it is and why it matters
CVE-2026-48282 is a path traversal flaw (improper limitation of a pathname to a restricted directory) in Adobe ColdFusion [1]. In simple terms, an attacker can manipulate the file paths that the application processes in order to escape the folder where it should be confined and access or interact with parts of the system that are not supposed to be accessible. According to the official description, this weakness can lead to arbitrary code execution in the context of the user running the service, and it does not require any interaction from the victim to be exploited [1].
The combination of three factors explains why this alert deserves priority attention: the severity score is the maximum possible (CVSS 10.0) [1], no one needs to click anything or make a mistake for the attack to work [1], and active exploitation has already been recorded according to the CISA KEV catalog [2]. When these three elements coincide, the margin for reacting "calmly" is considerably reduced.
Who is affected
It specifically affects organizations that have Adobe ColdFusion deployed in versions 2025.9, 2023.20 or earlier [1]. ColdFusion is commonly used as a platform for developing and running enterprise web applications, internal portals, intranets, and customer-facing services, so the risk is not limited to the IT department: a compromised server can expose customer data, internal credentials, or serve as an entry point into the rest of the corporate network. If you are not certain whether any system in your company (in-house or from a vendor) runs on ColdFusion, now is a good time to ask.
How to know if you are vulnerable
The first step is a basic inventory: confirm whether any Adobe ColdFusion server is active, which specific version it is running, and whether it is accessible from the internet or only from the internal network. These servers have often been running for years "because they've always been there," and no one has them mapped as a critical asset, which is precisely the type of exposed surface that should be reviewed systematically and not only when an alert goes off. Our intelligence radar at OCIRIA tracks this type of vulnerability by cross-referencing the same public data from NVD and CISA KEV cited in this article —this is not a separate additional source, but an internal analysis of that same information [1][2]— to prioritize alerts like this one based on actual severity and confirmed exploitation, helping companies distinguish noise from what is truly urgent.
How to protect yourself
- Identify all ColdFusion servers in your organization and those of third parties that provide you service, including test or legacy environments.
- Verify the installed version against the affected ones (2025.9, 2023.20 and earlier) [1].
- Apply the patch or update published by Adobe as soon as it is available for your version; since this is a vulnerability already being exploited according to CISA KEV [2], this action should not be postponed.
- Restrict access to ColdFusion administrative interfaces, limiting it by IP or VPN whenever possible, while patching is completed.
- Review logs for access and errors, looking for unusual patterns of uncommon file paths.
- Segment the network so that a compromised ColdFusion server does not provide direct access to critical systems.
Frequently asked questions
Is it urgent to act now?
Yes. The maximum severity (CVSS 10.0) [1] and the confirmed active exploitation in CISA KEV [2] are clear signals that this review should be prioritized over other maintenance tasks.
Does it affect all versions of ColdFusion?
The official data points to versions 2025.9, 2023.20 and earlier [1]. If you have a different version, confirm it with your vendor or technical team as well, since it is worth verifying on a case-by-case basis.
Do I need user interaction for this vulnerability to be exploited?
No. According to the official description, exploitation does not require user interaction [1], which makes it more dangerous than other flaws that depend on tricking someone.
What is CISA KEV and why does it matter that it's listed there?
It is the catalog of known exploited vulnerabilities maintained by the US cybersecurity agency. A CVE being listed there means there is evidence of real, ongoing attacks, not just a theoretical risk [2].
Sources
- [1] https://nvd.nist.gov/vuln/detail/CVE-2026-48282
- [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json