we_are_coded.by CODE · The world, decoded
БГ
CISA

A vulnerability in Adobe ColdFusion scored 10.0 is being actively exploited

CISASecurity

CISA added CVE-2026-48282 to the Known Exploited Vulnerabilities catalog over evidence of active exploitation. NVD scores it 10.0 on CVSS - the maximum value. Federal agencies have until 10 July.

In short
  • CVE-2026-48282 (Adobe ColdFusion, path traversal, CVSS 10.0) is in the KEV over proven active exploitation.
  • The patch is in APSB26-68; affected are ColdFusion 2025.9 and 2023.20 and older. Deadline for federal agencies: 10 July.
  • We pulled the same bulletin on 6 July because an aggregator claimed exploitation that Adobe denied. Today CISA confirms it - for a different CVE.
Checked on8 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Two days ago we pulled an article about the same bulletin from Adobe. Today we're writing it - but about a different vulnerability, for a different reason. It's worth explaining why.

The facts: On 7 July 2026, CISA added CVE-2026-48282 (path traversal in Adobe ColdFusion, an old web application platform) to the Known Exploited Vulnerabilities catalog over evidence of active exploitation. NVD (the US vulnerability database) gives it a CVSS 3.1 score of 10.0 (critical). Affected are ColdFusion 2025.9 and 2023.20 and older versions; the patch is in Adobe bulletin APSB26-68. The deadline for US federal agencies is 10 July 2026. Primary source: CISA's official KEV catalog (catalogVersion 2026.07.07) and NVD.

On 6 July an aggregator claimed a vulnerability from bulletin APSB26-68 was being actively exploited. We opened Adobe's official page: it said the opposite. We killed the article. Today CISA confirms active exploitation - for a DIFFERENT vulnerability from the same bulletin.

The aggregator got the direction right and the fact wrong. That's not half a win. That's the reason we don't cite it.

So: the difference between 'something in this bulletin is going to blow up' and 'CVE-2026-48282 is blowing up' is the difference between a hunch and an action. On the first, you can't patch anything. On the second, you know exactly which server, which version, by when. Had we published the guess, we'd be 'first' with a piece that does no work.

ColdFusion is one of those systems nobody remembers is running - until the day someone finds it. A score of 10.0 is the ceiling of the scale, there's nothing higher. In practice: access to files outside the application, no password needed.

If you have ColdFusion anywhere in your infrastructure, the patch doesn't wait for the next maintenance window. And if someone tells you something is being exploited - ask for the CVE number. No number, no news.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Adds One Known Exploited Vulnerability to Catalog (07.07.2026)→CISA - Known Exploited Vulnerabilities Catalog→NVD - CVE-2026-48282
Original: https://wearecoded.com/en/articles/coldfusion-cvss10-kev-exploited.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news