IMAGE CREDITS: COREWIRE / AI ILLUSTRATION

Adobe’s 10.0-severity ColdFusion flaw is already being exploited

CVE-2026-48282, a path traversal flaw in ColdFusion’s Remote Development Services, scores a maximum CVSS 10.0 and allows unauthenticated code execution. Researchers reported in-the-wild attacks within hours of disclosure.

A vulnerability does not get worse than this one. CVE-2026-48282, a path traversal flaw in Adobe ColdFusion, carries a maximum CVSS score of 10.0, requires no authentication, and attackers are already using it. If your organisation runs ColdFusion and has not patched, this is a today problem, not a this-week problem.

The flaw sits in ColdFusion’s Remote Development Services, specifically the RDS FILEIO handler, and it is one of the ugliest kinds in enterprise software: an unauthenticated attacker can write files anywhere on the filesystem, including the web root, which converts directly into remote code execution.

The timeline that matters

Adobe published advisory APSB26-68 on June 30 with patches: ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. At release, Adobe said it was not aware of in-the-wild exploitation. That changed almost immediately. Security researchers reported active attacks beginning within hours of disclosure, with exploitation tracked publicly by KEVIntel. Affected versions include 2025.9, 2023.20 and earlier.

What to do now

Patch to Update 10 or Update 21 immediately. If patching today is impossible, disable RDS, which should not be exposed on production servers in the first place, and audit web roots for unexpected files as a compromise check. ColdFusion has a long history of powering quiet, critical internal applications that nobody remembers until an incident, which is precisely why attackers keep returning to it.

What to watch

Watch for CISA adding CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, which would trigger mandatory patching deadlines for US federal agencies, and for the first public post-mortems naming victims. Both tend to follow within days of exploitation at this scale.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading