CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68

cve · CVE-2026-48281

Coverage
1
first 2026-07-02 → last 2026-07-02
Latest activity
2026-07-08
CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology
Sources cited
6
3 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-48281, newest first. Check the date before acting on an older one.

  • Confirm every internet-facing ColdFusion 2025/2023 instance is on 2025 Update 10 / 2023 Update 21; treat any unpatched instance as compromised and hunt before patching.
    2026-07-02CVE-2026-48276 +5
  • Review ColdFusion upload/writable paths (cf_scripts, CFIDE, admin upload directories) for newly written .jsp/.cfm/.cfc files outside deployment windows.
    2026-07-02CVE-2026-48276 +5

Defender insights

What each entry about CVE-2026-48281 tells a defender to do, newest first.

Story timeline

  1. 2026-07-02CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths
    trending-vulnerabilities

Entries about Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 (1)

2026-07-02 · view entry permalink →

HIGHCVE-2026-48276 +5exploitedupdated

CVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths

Adobe's 2026-06-30 bulletin APSB26-68 fixes six maximum-severity (CVSS 10.0) remote-code-execution flaws in ColdFusion 2025 (≤ Update 9) and 2023 (≤ Update 20): two CWE-434 unrestricted-file-upload paths (CVE-2026-48276, CVE-2026-48283), three CWE-20 improper-input-validation paths (CVE-2026-48277, CVE-2026-48281, CVE-2026-48316) and one CWE-22 path-traversal path (CVE-2026-48282). All are network-exploitable with no authentication and no user interaction (AV:N/AC:L), and every fix is rated Adobe Priority 1 ("high risk of being targeted"); Adobe states it is "not aware of any exploits in the wild for any of the issues addressed in these updates" (Adobe PSIRT APSB26-68, 2026-06-30). A parallel same-day bulletin, APSB26-69, fixes a CVSS 10.0 CWE-863 incorrect-authorization code-execution flaw (CVE-2026-48286) in on-prem Campaign Classic 7.4.3 build 9396 and earlier, resolved in build 9397; Adobe-hosted instances were remediated server-side (Adobe PSIRT APSB26-69, 2026-06-30). ColdFusion's history of rapid weaponisation of unauth file-upload / path-traversal primitives makes this a same-week patch priority for any internet-facing instance even absent confirmed exploitation. Fixed in ColdFusion 2025 Update 10 and 2023 Update 21; given the unauthenticated file-upload class, review upload directories (cf_scripts, CFIDE, admin upload paths) for newly written .jsp/.cfm/.cfc files outside deployment windows (Adobe PSIRT APSB26-68, 2026-06-30).

Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.

KEVIntel, via BleepingComputer

can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems

BleepingComputer
Updaterun 2026-07-08T2009Z-intelactionscvesentitiesevidencesourcestagsbody

The 2026-07-02 entry covered Adobe's APSB26-68/69 cluster (six CVSS 10.0 unauthenticated ColdFusion RCE paths plus a Campaign Classic flaw) while Adobe stated it was "not aware of any exploits in the wild." That status has now changed for one member of the cluster. CVE-2026-48282, the CWE-22 path-traversal path, is the first of the six confirmed exploited: KEVIntel reported in-the-wild exploitation captured across its honeypot network within under two hours of the technical details going public (BleepingComputer, 2026-07-06). CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on 7 July (CISA KEV, 2026-07-07), and BleepingComputer reports Shadowserver telemetry putting internet-exposed ColdFusion instances at roughly 800 (BleepingComputer, 2026-07-08). The remaining five cluster CVEs (CVE-2026-48276/-48277/-48281/-48283/-48316) remain unconfirmed for exploitation as of this run, but the sub-two-hour weaponisation of the first path is the operational signal that the whole cluster is being probed.

vulnerability02 Jul 04:55Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com3 (50%)
  • helpx.adobe.com2 (33%)
  • cisa.gov1 (17%)