Adobe ColdFusion is facing active exploitation of CVE-2026-48282, a maximum-severity flaw tied to RDS arbitrary file write that can be abused without privileges on unpatched servers. The Canadian Centre for Cyber Security warned that open-source reporting indicates in-the-wild attacks, while Adobe has issued security updates and urged administrators to patch immediately because of the high risk of compromise. Affected releases include ColdFusion 2025.9, 2023.20, and earlier, and internet scanning data from Shadowserver shows nearly 800 ColdFusion instances exposed online, though the number still vulnerable is unclear.
Separate reporting on CVE-2026-48276 highlights a closely related ColdFusion attack path in which an unauthenticated attacker uploads a malicious CFML payload through an unrestricted file-upload weakness, writes a web shell into a web-accessible location, and then triggers it with an HTTP request to gain code execution. That issue was described as critical with a CVSS v3.1 score reflecting full impact to confidentiality, integrity, and availability, and its documented root causes included poor filename and extension validation and storing uploads under the web root. Public detection content has also appeared for CVE-2026-48282, underscoring defender focus on identifying exposed and unpatched ColdFusion systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Akamai announced deployment of Adaptive Security Engine Rapid Rule 3000985 in App & API Protector to detect exploit attempts targeting Adobe ColdFusion CVE-2026-48282. The company said the rule addresses attacks against the RDS FILEIO path traversal flaw while emphasizing that Adobe's patches remain the primary mitigation.
CISA directed U.S. federal civilian agencies to patch the actively exploited Adobe ColdFusion flaw CVE-2026-48282 by Friday under Binding Operational Directive 26-04. The order followed the vulnerability's addition to the KEV catalog and elevated remediation urgency across federal networks.
CISA added Adobe ColdFusion vulnerability CVE-2026-48282 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The listing formalized the flaw's exploited status and increased urgency for organizations to patch affected ColdFusion systems.
The Canadian Centre for Cyber Security warned that attackers are actively exploiting CVE-2026-48282 in the wild. CCCS cited open-source reporting on exploitation and urged defenders to apply Adobe's updates, while public internet scans showed nearly 800 exposed ColdFusion instances.
Adobe released security updates for CVE-2026-48282, a maximum-severity remote code execution flaw affecting ColdFusion 2025.9, 2023.20, and earlier. Adobe urged administrators to patch immediately because of the high risk of exploitation.
A GitHub pull request was published for a Nuclei template covering CVE-2026-48282, identified there as an Adobe ColdFusion RDS arbitrary file write issue. The visible activity showed repository workflow actions such as assignment, labeling, and a YAML update for the CVE entry.
On July 2, 2026, the Canadian Centre for Cyber Security published advisory AV26-647 Update 1, citing Adobe's June 30 advisories for ColdFusion and Adobe Campaign Classic and noting open-source reporting that CVE-2026-48282 was being actively exploited. CCCS urged users and administrators to review Adobe's advisories and apply the necessary updates.
KEVIntel honeypot sensors detected exploitation attempts targeting Adobe ColdFusion CVE-2026-48282 on July 2, 2026. The activity showed attackers were probing the RDS-related path traversal flaw shortly after public technical analysis of the ColdFusion bugs appeared.
Adobe patched CVE-2026-48282 on June 30, 2026 in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. The flaw was described as a critical path traversal issue that can lead to arbitrary code execution and was addressed alongside five other maximum-severity ColdFusion vulnerabilities.
A report described CVE-2026-48276 as a critical unauthenticated unrestricted file upload vulnerability in Adobe ColdFusion that can lead to remote code execution via a web shell. The write-up included exploitation mechanics, root cause details, and a patched approach for safer file handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
orca.security
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceakamai.com
Open sourcecyber.gc.ca
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcedashboard.shadowserver.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.