Attackers are actively exploiting CVE-2026-48282, a maximum-severity Adobe ColdFusion path-traversal vulnerability rated CVSS 10.0. The flaw permits unauthenticated arbitrary file writes that can lead to remote code execution when Remote Development Services (RDS) is enabled with RDS authentication disabled—a non-default configuration. Adobe released patches on June 30, 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 7 following exploitation reports and a Canadian Centre for Cyber Security warning. CrowdSec first observed exploitation on July 20 and recorded 107 attacking IP addresses; separate telemetry cited by Previdian recorded 272 attempts across 16 sensors.
ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21 address this flaw and the related arbitrary-file-read vulnerability CVE-2026-48313, which CrowdSec also reports is being exploited. Organizations should prioritize patching exposed ColdFusion servers, verify whether RDS is enabled without authentication, and investigate potentially affected systems for unauthorized file writes and execution. Citrix released NetScaler Web App Firewall signatures version 183 to help mitigate exploitation, but these protections should supplement rather than replace patching. CrowdSec characterized the observed campaign as rapidly reaching Early Exploitation before settling into Limited Exploitation.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
By July 24, CrowdSec had classified activity against CVE-2026-48282 as Early Exploitation, four days after its first observed attack.
CrowdSec first observed exploitation of CVE-2026-48282 on its network, five days after deploying its detection rule.
CrowdSec deployed a detection rule to identify exploitation attempts against the ColdFusion RDS path traversal vulnerability.
Adobe disclosed and patched CVE-2026-48282 and the related arbitrary-file-read flaw CVE-2026-48313 in security bulletin APSB26-68. The fixes were included in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21.
Sina Kheirkhah of watchTowr Labs published technical analysis mapping the RDS file-write and file-read primitives to CVE-2026-48282 and CVE-2026-48313.
CrowdSec reported observing exploitation of the related ColdFusion arbitrary-file-read vulnerability CVE-2026-48313. The flaw abuses the same RDS ACTION=FILEIO interface and can expose files accessible to the ColdFusion service.
Following the Early Exploitation phase, CrowdSec classified the activity as Limited Exploitation. It attributed the plateau to the smaller population of exposed servers with RDS enabled and RDS authentication disabled.
Citrix released NetScaler Web App Firewall signatures version 183 to help mitigate several vulnerabilities, including CVE-2026-48282. Its excerpt described the ColdFusion flaw as an arbitrary file upload issue, differing from the path traversal description in other reports.
CISA added the ColdFusion path traversal vulnerability to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
BleepingComputer and DarkWebInformer reported active exploitation of the maximum-severity ColdFusion vulnerability. BleepingComputer cited a warning from the Canadian Centre for Cyber Security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
crowdsec.net
Open sourceprevidian.com
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.