---
schema: 1
kind: vulnerability
title: >
  CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0
  unauthenticated RCE paths
headline: >
  CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0
  unauthenticated RCE paths
summary: >
  Seven max-severity Adobe flaws land in one week. Adobe's 30 June bulletins fix six CVSS 10.0
  unauthenticated RCE paths in ColdFusion 2025/2023 (file-upload, input-validation and
  path-traversal classes) plus a CVSS 10.0 authorization-bypass code-execution flaw in Campaign
  Classic — all Priority 1, no exploitation reported yet (Adobe PSIRT). ColdFusion's exploitation
  history makes this a same-week patch for internet-facing instances.
discovered_at: "2026-07-02T04:55:20Z"
updated_at: "2026-07-08T20:35:00Z"
event_date: 2026-06-30
run_id: 2026-07-02-6551f8c2
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - path-traversal
  - patch-available
  - actively-exploited
  - cisa-kev
regions:
  - global
sectors:
  - public-sector
  - technology
entities:
  - "trend:adobe-coldfusion-campaign-apsb26-68-69"
techniques: []
affected_products: []
cves:
  - id: CVE-2026-48276
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48277
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48281
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48282
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: "ColdFusion 2025 ≤ Update 9, 2023 ≤ Update 20"
    fixed: "ColdFusion 2025 Update 10, 2023 Update 21"
  - id: CVE-2026-48283
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-48316
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html"
    publisher: Adobe PSIRT APSB26-68
    role: primary
  - url: "https://helpx.adobe.com/security/products/campaign/apsb26-69.html"
    publisher: Adobe PSIRT APSB26-69
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/"
    publisher: BleepingComputer
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/"
    publisher: BleepingComputer
    date: 2026-07-06
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday/"
    publisher: BleepingComputer
    date: 2026-07-08
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: CISA Known Exploited Vulnerabilities Catalog
    date: 2026-07-07
    role: corroborating
closed_sources: []
evidence:
  - quote: "Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network."
    publisher: "KEVIntel, via BleepingComputer"
  - quote: can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems
    publisher: BleepingComputer
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Confirm every internet-facing ColdFusion 2025/2023 instance is on 2025 Update 10 / 2023 Update 21; treat any unpatched instance as compromised and hunt before patching."
  - "Review ColdFusion upload/writable paths (cf_scripts, CFIDE, admin upload directories) for newly written .jsp/.cfm/.cfc files outside deployment windows."
updates:
  - at: "2026-07-08T20:35:00Z"
    run_id: 2026-07-08T2009Z-intel
    type: update
    summary: >
      CVE-2026-48282, one of the six CVSS 10.0 unauthenticated ColdFusion RCE flaws Adobe patched on 1
      July, is now confirmed exploited in the wild and was added to CISA KEV on 7 July. Any
      internet-facing ColdFusion 2025.9 / 2023.20-or-earlier instance not yet on the 1 July fix should
      be treated as under active attack, not merely at risk.
    fields:
      - actions
      - cves
      - entities
      - evidence
      - sources
      - tags
      - body
    merged_from: 2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev
migrated_from: briefs/2026-07-02.md
---

Adobe's 2026-06-30 bulletin APSB26-68 fixes six maximum-severity (CVSS 10.0) remote-code-execution flaws in ColdFusion 2025 (≤ Update 9) and 2023 (≤ Update 20): two CWE-434 unrestricted-file-upload paths (CVE-2026-48276, CVE-2026-48283), three CWE-20 improper-input-validation paths (CVE-2026-48277, CVE-2026-48281, CVE-2026-48316) and one CWE-22 path-traversal path (CVE-2026-48282). All are network-exploitable with no authentication and no user interaction (AV:N/AC:L), and every fix is rated Adobe Priority 1 ("high risk of being targeted"); Adobe states it is "not aware of any exploits in the wild for any of the issues addressed in these updates" ([Adobe PSIRT APSB26-68, 2026-06-30](https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html)). A parallel same-day bulletin, APSB26-69, fixes a CVSS 10.0 CWE-863 incorrect-authorization code-execution flaw (CVE-2026-48286) in on-prem Campaign Classic 7.4.3 build 9396 and earlier, resolved in build 9397; Adobe-hosted instances were remediated server-side ([Adobe PSIRT APSB26-69, 2026-06-30](https://helpx.adobe.com/security/products/campaign/apsb26-69.html)). ColdFusion's history of rapid weaponisation of unauth file-upload / path-traversal primitives makes this a same-week patch priority for any internet-facing instance even absent confirmed exploitation. Fixed in ColdFusion 2025 Update 10 and 2023 Update 21; given the unauthenticated file-upload class, review upload directories (`cf_scripts`, `CFIDE`, admin upload paths) for newly written `.jsp`/`.cfm`/`.cfc` files outside deployment windows ([Adobe PSIRT APSB26-68, 2026-06-30](https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html)).

## Update — 2026-07-08T20:35:00Z

The 2026-07-02 entry covered Adobe's APSB26-68/69 cluster — six CVSS 10.0 unauthenticated ColdFusion RCE paths plus a Campaign Classic flaw — while Adobe stated it was "not aware of any exploits in the wild." That status has now changed for one member of the cluster. CVE-2026-48282, the CWE-22 path-traversal path, is the first of the six confirmed exploited: KEVIntel reported in-the-wild exploitation captured across its honeypot network within under two hours of the technical details going public ([BleepingComputer, 2026-07-06](https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/)). CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on 7 July ([CISA KEV, 2026-07-07](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)), and BleepingComputer reports Shadowserver telemetry putting internet-exposed ColdFusion instances at roughly 800 ([BleepingComputer, 2026-07-08](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday/)). The remaining five cluster CVEs (CVE-2026-48276/-48277/-48281/-48283/-48316) remain unconfirmed for exploitation as of this run — but the sub-two-hour weaponisation of the first path is the operational signal that the whole cluster is being probed. **Defender takeaway:** the 1 July patch is now an emergency item for any exposed instance, not a same-week hygiene task; given the unauthenticated file-upload/path-traversal class, an unpatched instance should be hunted for planted web shells before it is patched.
