Attackers are actively exploiting CVE-2026-48282, a critical vulnerability in Adobe ColdFusion with a CVSS score of 10.0, mere days after its public disclosure and patch release. The vulnerability affects Adobe ColdFusion version 2023. The article confirms exploitation attempts but does not provide specific details on the attack vector, a fixed version number, or a workaround.
CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel, mere minutes after watchTowr researchers published a technical analysis of this and other ColdFusion flaws recently fixed by Adobe. What makes CVE-2026-48282 dangerous Adobe ColdFusion is a widely used development platform for building and deploying enterprise-grade … More → The post Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) appeared first on Help Net Security .