CVE Tools

Max severity Adobe ColdFusion flaw now exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedColdFusion

Our summary

Attackers are exploiting a max-severity Adobe ColdFusion vulnerability, CVE-2026-48282, with KEVIntel reporting in-the-wild use shortly after public details emerged. The issue affects ColdFusion versions 2025.9, 2023.20, and earlier and can enable remote code execution without needing attacker privileges, making unpatched systems a priority risk. Adobe has released fixes and urged administrators to apply updates immediately, with Canadian and other monitoring efforts also warning defenders to remediate.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store