CVE Tools

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)

Help Net SecurityBy Zeljka Zorz

Reported exploitedAdobe ColdFusion

Our summary

Active exploitation attempts have been observed against Adobe ColdFusion shortly after patches were released on June 30, 2026. The targeted issue is CVE-2026-48282, a path traversal vulnerability that can be abused by remote, unauthenticated attackers to upload a malicious file and trigger arbitrary code execution via a web-accessible location. This matters because attackers can leverage the Remote Development Services (RDS) feature when it is enabled and access is not properly restricted, so organizations running affected ColdFusion versions should urgently update and hunt for suspicious artifacts.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store