Adobe ColdFusion CVE-2026-48282 exploited within days of patch
Attackers began exploiting CVE-2026-48282, a maximum-severity path traversal flaw in Adobe ColdFusion's Remote Development Services that allows unauthenticated remote code execution, shortly after Adobe patched it on 30 June 2026.
- Victim
- Adobe ColdFusion deployments
In early July 2026, attackers began exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion that Adobe had patched on 30 June 2026 alongside nine other critical flaws. The bug is a path traversal in the Remote Development Services (RDS) file I/O handler that lets an unauthenticated attacker write files and achieve remote code execution on the server.
Vulnerability-intelligence firm KEVIntel detected exploitation attempts against its honeypots on 2 July, the same day watchTowr researchers published a technical analysis. On 7 and 8 July, the flaw was added to CISA's Known Exploited Vulnerabilities catalog, with U.S. federal civilian agencies ordered to remediate by 10 July.
Exposure
Exploitation requires RDS to be enabled with RDS authentication disabled, which is not the default configuration, limiting the pool of vulnerable servers. The Shadowserver Foundation tracked roughly 750 internet-facing ColdFusion servers. Fixed versions are ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, and defenders were advised to hunt for unexpected files in the web root and the /CFIDE/ directory.
Why it matters
ColdFusion remains common in government, financial and healthcare web stacks, and it has a long history of being exploited soon after patches are released. The near-immediate weaponization of CVE-2026-48282 is another sign that the window between a patch and mass exploitation is now measured in hours or days, which leaves organizations with slow patch cycles exposed by default.
Timeline
Adobe patches CVE-2026-48282 and nine other critical ColdFusion flaws in a security bulletin.
KEVIntel honeypot sensors capture in-the-wild exploitation; watchTowr publishes technical analysis.
Exploitation is widely reported; CISA adds the flaw to its Known Exploited Vulnerabilities catalog and sets a 10 July remediation deadline for federal agencies.
Sources
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/07/07/adobe-coldfusion-cve-2026-48282-exploitation-detected/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/
- securityweek.comhttps://www.securityweek.com/critical-adobe-coldfusion-vulnerability-exploited-in-attacks/