Hackers Exploit Maximum-Severity Adobe ColdFusion Flaw Within Hours of Disclosure

Attackers are actively exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, which enables remote code execution on unpatched systems without requiring any privileges. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier releases of the popular enterprise web application development platform. Adobe released security updates on July 1 and urged administrators to deploy patches within 72 hours due to a high risk of exploitation.

Vulnerability intelligence firm KEVIntel reports that threat actors began exploiting the vulnerability within just two hours of Adobe's public disclosure. The company's founder Ryan Dewhurst confirmed that in-the-wild exploitation was captured through their global honeypot network almost immediately after details went public. The Canadian Centre for Cyber Security has also issued an alert encouraging administrators to apply the necessary updates as soon as possible.

Security monitoring group Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed online, though it remains unclear how many of those systems are already secured against the ongoing attacks. This vulnerability was part of a broader patch release from Adobe that addressed six maximum-severity flaws across ColdFusion and Campaign Classic platforms, all of which are exploitable through low-complexity attacks that require no user interaction.

Read More at the original source →