Alastor InfoSec
← Back to Blog
Vulnerability

July 10, 2026 · Alastor InfoSec Team

CVE-2026-48282: Adobe ColdFusion CVSS 10.0 Flaw Actively Exploited — Patch Immediately

A critical vulnerability in Adobe ColdFusion — CVE-2026-48282, CVSS score 10.0 — is being actively exploited in the wild. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog and set a federal patch deadline of July 10, 2026 (today). If you're running ColdFusion and haven't patched, assume you're a target.

What the vulnerability is

CVE-2026-48282 is a path traversal flaw in ColdFusion's Remote Development Services (RDS) FILEIO handler — specifically the endpoint at /CFIDE/main/ide.cfm?ACTION=FILEIO. The vulnerability allows an unauthenticated attacker to write arbitrary files to the server's filesystem.

In practice: attackers are using it to upload CFML webshells containing <cfexecute> tags, which gives them full remote code execution running as the ColdFusion service account — NT AUTHORITY\SYSTEM on Windows servers.

No authentication is required when RDS authentication is disabled, which is common in enterprise deployments that treat the RDS interface as internal-only. It isn't.

How fast exploitation followed disclosure

Adobe patched CVE-2026-48282 on June 30, 2026 as part of security bulletin APSB26-68 — a bulletin that addressed 11 ColdFusion vulnerabilities in total, including seven rated CVSS 10.0.

Exploitation began on July 2 — two days after the patch, and within minutes of watchTowr researchers publishing their technical analysis. Threat intelligence sensors picked up the first exploit attempt, originating from an IP geolocated to India, and the volume of attempts has grown since.

This is the standard exploit timeline now: a patch ships, researchers publish technical details, attackers weaponise within hours. The window between "patch available" and "active exploitation" is measured in days, not weeks.

Affected versions

  • Adobe ColdFusion 2025, Update 9 and earlier
  • Adobe ColdFusion 2023, Update 20 and earlier

If you are on either of these product lines and haven't applied the June 30 patch (APSB26-68), you are running a remotely exploitable, unauthenticated CVSS 10.0 vulnerability.

What attackers are doing with access

Webshell access via ColdFusion gives attackers a persistent foothold on the web server. From there, the typical progression looks like:

  1. Lateral movement — the ColdFusion server is usually on an internal network segment with database access, credentials in config files, and AD connectivity.
  2. Credential harvesting — ColdFusion datasource configurations store database credentials in plaintext; attackers exfiltrate these immediately.
  3. Ransomware staging or data exfiltration — with SYSTEM-level access, attackers can disable AV, install persistent backdoors, and move large volumes of data before you notice.

The organisations most at risk are those where ColdFusion is running older, internet-facing applications that aren't regularly assessed — government portals, healthcare systems, and enterprise applications built on ColdFusion in the 2000s that never got migrated.

Immediate remediation steps

1. Patch now. Apply Adobe Security Bulletin APSB26-68. Update to ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21 (or later).

2. Check for existing compromise. Before or alongside patching, look for:

  • New files in /CFIDE/ or your webroot with recent modification timestamps
  • Unusual cfexecute calls in your ColdFusion logs
  • Outbound connections from the ColdFusion process to unfamiliar IPs
  • New scheduled tasks or services created around or after July 2

3. Restrict RDS. If RDS is not actively used for development, disable it entirely at the web server level — not just via ColdFusion admin settings.

4. Review your ColdFusion administrator exposure. The admin panel should never be reachable from the internet. If it is, restrict it to known IPs via network controls, not just application-layer authentication.

5. Deploy WAF rules. Temporary mitigation while patching is in progress: WAF rules blocking requests to /CFIDE/main/ide.cfm with ACTION=FILEIO in the query string will block the known exploit chain, though not necessarily variants.

What this looks like as a detection signal

If you're running SIEM or EDR, these indicators are worth hunting for right now:

  • HTTP POST requests to /CFIDE/main/ide.cfm?ACTION=FILEIO in your web server access logs
  • New .cfm files created in web-accessible directories after June 30
  • Process spawning from coldfusion.exe or jrun.exe that isn't typical application behaviour
  • DNS lookups or outbound connections from the ColdFusion process to non-standard destinations

The broader picture: Adobe's CVSS 10.0 streak

This isn't an isolated incident. The same APSB26-68 bulletin patched seven separate CVSS 10.0 vulnerabilities in Adobe ColdFusion and Campaign Classic. Adobe's ColdFusion codebase has a long history of critical remote code execution vulnerabilities — CVE-2023-26360, CVE-2024-20767, and now CVE-2026-48282 are all in the same product line, all exploited in the wild, all within the past three years.

If your organisation is still running ColdFusion in production, this isn't a one-time patch situation. It's a standing obligation to maintain a continuous testing posture against a product that is consistently and predictably targeted.

How Alastor InfoSec helps

Alastor Pulse identifies unpatched critical vulnerabilities like CVE-2026-48282 across your attack surface and surfaces them with verified exploitability context — not just a CVE number but confirmation of whether the specific configuration in your environment is reachable and exploitable. For ColdFusion deployments specifically, our DAST and manual penetration testing cover the RDS endpoint, admin panel exposure, and webshell detection as part of standard web application scope.

If you want a rapid assessment of your ColdFusion exposure, reach out and we can turn it around fast.


Adobe APSB26-68 is available at adobe.com/security/products/coldfusion. Patch. Today.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.