A vulnerability does not get worse than this one. CVE-2026-48282, a path traversal flaw in Adobe ColdFusion, carries a maximum CVSS score of 10.0, requires no authentication, and attackers are already using it. If your organisation runs ColdFusion and has not patched, this is a today problem, not a this-week problem.
The flaw sits in ColdFusion’s Remote Development Services, specifically the RDS FILEIO handler, and it is one of the ugliest kinds in enterprise software: an unauthenticated attacker can write files anywhere on the filesystem, including the web root, which converts directly into remote code execution.
The timeline that matters
Adobe published advisory APSB26-68 on June 30 with patches: ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. At release, Adobe said it was not aware of in-the-wild exploitation. That changed almost immediately. Security researchers reported active attacks beginning within hours of disclosure, with exploitation tracked publicly by KEVIntel. Affected versions include 2025.9, 2023.20 and earlier.
What to do now
Patch to Update 10 or Update 21 immediately. If patching today is impossible, disable RDS, which should not be exposed on production servers in the first place, and audit web roots for unexpected files as a compromise check. ColdFusion has a long history of powering quiet, critical internal applications that nobody remembers until an incident, which is precisely why attackers keep returning to it.
The hours-not-days era of exploitation
The detail in this incident with the longest shelf life is the gap between advisory and attack: hours. That compression is structural, not situational. A published patch is a map to the vulnerability, attackers diff the patched code against the old version, locate the fix, and work backward to the exploit, and automation has industrialized every step of that pipeline. The old operating assumption, that an organization had days or weeks to schedule patching after an advisory, described a world where exploit development was artisanal. It no longer is.
That changes what preparedness means for internet-facing software. Emergency patching for critical advisories has to be a rehearsed procedure with a same-day service-level target, not a calendar entry, and the compensating controls matter precisely because same-day is not always possible: services like RDS that should never face the internet are the difference between a vulnerable version and an exploitable one. The pattern is now the norm across the sector, Microsoft’s record July Patch Tuesday shipped with exploitation already in progress, and it is a large part of why the security budget keeps defying gravity: the window between disclosure and attack is the one variable defenders cannot negotiate with.
What to watch
Watch for CISA adding CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, which would trigger mandatory patching deadlines for US federal agencies, and for the first public post-mortems naming victims. Both tend to follow within days of exploitation at this scale.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
