Adobe ColdFusion CVE-2026-48282 exploited within days of patch
Attackers began exploiting CVE-2026-48282, a maximum-severity path traversal flaw in Adobe ColdFusion's Remote Development Services that allows unauthenticated remote code execution, shortly after Adobe patched it on 30 June 2026.
- Victim
- Adobe ColdFusion deployments