• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-48282: pre-auth remote code execution in Adobe ColdFusion

A remote attacker can exploit a path traversal flaw in Adobe ColdFusion to achieve arbitrary code execution as the current user. CVE-2026-48282 affects ColdFusion 2025 branch 9.x (9 and earlier) and ColdFusion 2023 branch 20.x (20 and earlier). The issue changes scope and can be triggered without user interaction or authentication over the network, allowing code execution with network access to the vulnerable service.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.42388
CWE
CWE-22
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA added this vulnerability to its KEV catalog with a short remediation deadline, and public exploit code exists; prioritize mitigations or vendor guidance immediately for internet-facing ColdFusion instances.

What is CVE-2026-48282?

A remote attacker can exploit a path traversal flaw in Adobe ColdFusion to achieve arbitrary code execution as the current user. CVE-2026-48282 affects ColdFusion 2025 branch 9.x (9 and earlier) and ColdFusion 2023 branch 20.x (20 and earlier). The issue changes scope and can be triggered without user interaction or authentication over the network, allowing code execution with network access to the vulnerable service. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Adobe ColdFusion are affected?

BRANCHAFFECTEDFIXED
ColdFusion 2025 9.x9 and earlier
ColdFusion 2023 20.x20 and earlier

Is CVE-2026-48282 being exploited?

CISA added CVE-2026-48282 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and U.S. federal agencies were required to address it by 2026-07-10; public exploit code is also available.

How to fix CVE-2026-48282

  1. Restrict access to ColdFusion services from untrusted networks and block internet exposure where possible.
  2. Apply any vendor mitigations and configuration guidance recommended for ColdFusion immediately.
  3. Monitor ColdFusion logs and host telemetry for suspicious file access and remote code execution indicators.
  4. Follow CISA’s KEV instructions and BOD 26-04 guidance; discontinue use or move to a compensated managed service if mitigations are unavailable.

Frequently asked questions

Is CVE-2026-48282 being actively exploited?

CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on 2026-07-07, with a required remediation date of 2026-07-10 for federal agencies.

Which ColdFusion versions are affected by CVE-2026-48282?

ColdFusion 2025 branch 9.x (9 and earlier) and ColdFusion 2023 branch 20.x (20 and earlier) are listed as affected.

Is there a patch for CVE-2026-48282?

No vendor-fixed versions are listed in the available facts; follow Adobe’s guidance and apply provided mitigations until a patch is released.

Does CVE-2026-48282 require authentication?

No, exploitation does not require authentication or user interaction; a remote attacker with network access can trigger the issue.

References