CISA added CVE-2026-48282 to the Known Exploited Vulnerabilities catalog over evidence of active exploitation. NVD scores it 10.0 on CVSS - the maximum value. Federal agencies have until 10 July.
- CVE-2026-48282 (Adobe ColdFusion, path traversal, CVSS 10.0) is in the KEV over proven active exploitation.
- The patch is in APSB26-68; affected are ColdFusion 2025.9 and 2023.20 and older. Deadline for federal agencies: 10 July.
- We pulled the same bulletin on 6 July because an aggregator claimed exploitation that Adobe denied. Today CISA confirms it - for a different CVE.
Two days ago we pulled an article about the same bulletin from Adobe. Today we're writing it - but about a different vulnerability, for a different reason. It's worth explaining why.
On 6 July an aggregator claimed a vulnerability from bulletin APSB26-68 was being actively exploited. We opened Adobe's official page: it said the opposite. We killed the article. Today CISA confirms active exploitation - for a DIFFERENT vulnerability from the same bulletin.
So: the difference between 'something in this bulletin is going to blow up' and 'CVE-2026-48282 is blowing up' is the difference between a hunch and an action. On the first, you can't patch anything. On the second, you know exactly which server, which version, by when. Had we published the guess, we'd be 'first' with a piece that does no work.
ColdFusion is one of those systems nobody remembers is running - until the day someone finds it. A score of 10.0 is the ceiling of the scale, there's nothing higher. In practice: access to files outside the application, no password needed.
If you have ColdFusion anywhere in your infrastructure, the patch doesn't wait for the next maintenance window. And if someone tells you something is being exploited - ask for the CVE number. No number, no news.