A vulnerability does not get worse than this one. CVE-2026-48282, a path traversal flaw in Adobe ColdFusion, carries a maximum CVSS score of 10.0, requires no authentication, and attackers are already using it. If your organisation runs ColdFusion and has not patched, this is a today problem, not a this-week problem.
The flaw sits in ColdFusion’s Remote Development Services, specifically the RDS FILEIO handler, and it is one of the ugliest kinds in enterprise software: an unauthenticated attacker can write files anywhere on the filesystem, including the web root, which converts directly into remote code execution.
The timeline that matters
Adobe published advisory APSB26-68 on June 30 with patches: ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. At release, Adobe said it was not aware of in-the-wild exploitation. That changed almost immediately. Security researchers reported active attacks beginning within hours of disclosure, with exploitation tracked publicly by KEVIntel. Affected versions include 2025.9, 2023.20 and earlier.
What to do now
Patch to Update 10 or Update 21 immediately. If patching today is impossible, disable RDS, which should not be exposed on production servers in the first place, and audit web roots for unexpected files as a compromise check. ColdFusion has a long history of powering quiet, critical internal applications that nobody remembers until an incident, which is precisely why attackers keep returning to it.
What to watch
Watch for CISA adding CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, which would trigger mandatory patching deadlines for US federal agencies, and for the first public post-mortems naming victims. Both tend to follow within days of exploitation at this scale.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
