Brazil's CTIR Gov warned that Adobe ColdFusion is affected by a critical remote code execution flaw, tracked as CVE-2026-48282, that can allow arbitrary code execution on vulnerable servers. The alert says Adobe has released a security update and urges organizations to identify exposed or unsupported ColdFusion deployments and apply the vendor's fixes immediately.
The notice also states that CVE-2026-48282 has been added to CISA's Known Exploited Vulnerabilities catalog, indicating evidence of active exploitation in the wild. CTIR Gov highlighted the urgency for Brazilian REGIC member institutions to remediate the issue, and cited an EPSS score of 3.20% with an 86.59th percentile, underscoring the likelihood of exploitation and the need for rapid patching.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CTIR Gov published Alerta 55/2026 warning about critical Adobe ColdFusion vulnerability CVE-2026-48282 and urging organizations to identify vulnerable deployments and apply vendor fixes immediately. The notice also emphasized that Brazilian REGIC institutions must urgently remediate vulnerabilities highlighted in alerts and recommendations.
CVE-2026-48282 was listed in the CISA Known Exploited Vulnerabilities catalog, indicating reliable evidence of active exploitation in the wild. The CTIR Gov alert cites this KEV inclusion as part of its warning to defenders.
Adobe published a security update to remediate the critical ColdFusion vulnerability CVE-2026-48282, which can allow arbitrary code execution. The CTIR Gov notice references Adobe bulletin APSB26-68 for remediation details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.