Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48282 Under Active Exploitation (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- CVE-2026-48282 is a path traversal vulnerability with CVSS 10.0.
- Adobe released patches on June 30, 2026 in APSB26-68.
- 775 exposed ColdFusion instances exist, per ShadowServer Foundation.
"Attackers are exploiting a critical Adobe ColdFusion vulnerability (CVE-2026-48282, CVSS 10.0) that allows remote code execution. Adobe released patches on June 30, 2026, in bulletin APSB26-68. Researchers reported exploitation within hours of disclosure. There are approximately 775 exposed ColdFusion instances online. Adobe also announced a shift to bi-weekly security updates to address AI-accelerated vulnerability discovery."
no comments yet.