ctipilot.ch

Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68 — actively exploited, CISA KEV 2026-07-07

cve · CVE-2026-48282

Coverage timeline
2
first 2026-07-02 → last 2026-07-08
Peak priority
high
2 high
Sources cited
6
3 hosts
Sections touched
2
trending-vulnerabilities, updates
Co-occurring entities
6
see Related entities below
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-07-08CVE-2026-48282 — Adobe ColdFusion path-traversal RCE now actively exploited and CISA KEV-listed
    updatesAdobe ColdFusion path-traversal RCE (CVE-2026-48282) goes from patched-no-exploitation to KEV within a week
  2. 2026-07-02CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • updates1

Source distribution

  • bleepingcomputer.com3 (50%)
  • helpx.adobe.com2 (33%)
  • cisa.gov1 (17%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68 — actively exploited, CISA KEV 2026-07-07 (2)

2026-07-08 · view entry permalink →

HIGHCVE-2026-48282exploitedupdate

CVE-2026-48282 — Adobe ColdFusion path-traversal RCE now actively exploited and CISA KEV-listed

UPDATE · originally covered CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths (2026-07-02)

The 2026-07-02 entry covered Adobe's APSB26-68/69 cluster — six CVSS 10.0 unauthenticated ColdFusion RCE paths plus a Campaign Classic flaw — while Adobe stated it was "not aware of any exploits in the wild." That status has now changed for one member of the cluster. CVE-2026-48282, the CWE-22 path-traversal path, is the first of the six confirmed exploited: KEVIntel reported in-the-wild exploitation captured across its honeypot network within under two hours of the technical details going public (BleepingComputer, 2026-07-06). CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on 7 July (CISA KEV, 2026-07-07), and BleepingComputer reports Shadowserver telemetry putting internet-exposed ColdFusion instances at roughly 800 (BleepingComputer, 2026-07-08). The remaining five cluster CVEs (CVE-2026-48276/-48277/-48281/-48283/-48316) remain unconfirmed for exploitation as of this run — but the sub-two-hour weaponisation of the first path is the operational signal that the whole cluster is being probed.

Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.

KEVIntel, via BleepingComputer

can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems

BleepingComputer 2026-07-06
vulnerability08 Jul 20:35Zmulti-sourceOpen finding ↗

2026-07-02 · view entry permalink →

CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths

Adobe's 2026-06-30 bulletin APSB26-68 fixes six maximum-severity (CVSS 10.0) remote-code-execution flaws in ColdFusion 2025 (≤ Update 9) and 2023 (≤ Update 20): two CWE-434 unrestricted-file-upload paths (CVE-2026-48276, CVE-2026-48283), three CWE-20 improper-input-validation paths (CVE-2026-48277, CVE-2026-48281, CVE-2026-48316) and one CWE-22 path-traversal path (CVE-2026-48282). All are network-exploitable with no authentication and no user interaction (AV:N/AC:L), and every fix is rated Adobe Priority 1 ("high risk of being targeted"); Adobe states it is "not aware of any exploits in the wild for any of the issues addressed in these updates" (Adobe PSIRT APSB26-68, 2026-06-30). A parallel same-day bulletin, APSB26-69, fixes a CVSS 10.0 CWE-863 incorrect-authorization code-execution flaw (CVE-2026-48286) in on-prem Campaign Classic 7.4.3 build 9396 and earlier, resolved in build 9397; Adobe-hosted instances were remediated server-side (Adobe PSIRT APSB26-69, 2026-06-30). ColdFusion's history of rapid weaponisation of unauth file-upload / path-traversal primitives makes this a same-week patch priority for any internet-facing instance even absent confirmed exploitation. Fixed in ColdFusion 2025 Update 10 and 2023 Update 21; given the unauthenticated file-upload class, review upload directories (cf_scripts, CFIDE, admin upload paths) for newly written .jsp/.cfm/.cfc files outside deployment windows (Adobe PSIRT APSB26-68, 2026-06-30).

vulnerability02 Jul 04:55Zmulti-sourceOpen finding ↗