CVE-2026-48282: Adobe ColdFusion RDS Path Traversal Leading to RCE
ID: c9b24a1f-201f-5480-a891-c7b8339a0996
STIX ID: report--c9b24a1f-201f-5480-a891-c7b8339a0996
Feed Name: Resecurity
**Executive Summary:** Resecurity documents CVE-2026-48282, a critical unauthenticated path-traversal flaw in Adobe ColdFusion RDS FILEIO that allows arbitrary file write and unauthenticated remote code execution (CVSS 10.0); active exploitation has been observed and Adobe has released patches (ColdFusion 2025 Update 10 / 2023 Update 21). The report provides RPC request/PoC payloads, a full attack chain (discovery, write verification, webshell drop, execution, and post-exploitation), affected versions, impact analysis, and recommended immediate actions including patching, disabling or restricting RDS, hunting for webshells, rotating credentials, and network/host hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
