logo

Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10

ID: 1aa60b0d-a2f5-5c8b-8e43-a8149a1bddca

STIX ID: report--1aa60b0d-a2f5-5c8b-8e43-a8149a1bddca

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

**CVE-2026-48282 — Adobe ColdFusion (critical, CVSS 10.0):** a path traversal vulnerability enabling unauthenticated arbitrary code execution is being actively exploited in the wild; administrators must apply Adobe's emergency patches (ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21) immediately and isolate affected servers to prevent full server takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.