logo

CISA orders feds to patch max severity ColdFusion flaw by Friday

ID: 052e49d4-63c2-50fc-9ead-726674141b2d

STIX ID: report--052e49d4-63c2-50fc-9ead-726674141b2d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch a maximum-severity Adobe ColdFusion RCE vulnerability (CVE-2026-48282) that is being actively exploited; Adobe released updates, observers reported exploitation within hours of disclosure, Shadowserver tracks ~800 exposed instances, and the flaw was added to CISA's KEV catalog under a BOD 26-04 mitigation requirement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.