Attackers are actively exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, which enables remote code execution on unpatched systems without requiring any privileges. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier releases of the popular enterprise web application development platform. Adobe released security updates on July