CISA orders feds to patch max severity ColdFusion flaw by Friday
ID: 052e49d4-63c2-50fc-9ead-726674141b2d
STIX ID: report--052e49d4-63c2-50fc-9ead-726674141b2d
Feed Name: Bleeping Computer
Threat Score
CISA has ordered U.S. federal agencies to urgently patch a maximum-severity Adobe ColdFusion RCE vulnerability (CVE-2026-48282) that is being actively exploited; Adobe released updates, observers reported exploitation within hours of disclosure, Shadowserver tracks ~800 exposed instances, and the flaw was added to CISA's KEV catalog under a BOD 26-04 mitigation requirement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
