Security advisory
CybersecurityCriticalActive

Max-Severity Adobe ColdFusion Flaw CVE-2026-48282 Now Exploited in Attacks

The CCCS says open-source reporting confirms exploitation of the critical ColdFusion RCE, just two days after Adobe shipped emergency-grade patches.

Emanuel De AlmeidaJul 6, 2026, 8:01 PM4 min read
Severity
Critical
Status
Active
Entity
Adobe
Confirmed by
Canadian Center for Cyber Security (CCCS)

Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. The flaw allows unauthenticated attackers to gain remote code execution on unpatched systems, and Adobe released security updates addressing it earlier in the week.

With ColdFusion widely deployed for enterprise web applications and nearly 800 instances exposed online, an actively exploited unauthenticated RCE flaw creates immediate risk for organizations that have not yet applied Adobe's patches.

Key takeaways

  • CVE-2026-48282 is a maximum-severity Adobe ColdFusion flaw enabling unauthenticated remote code execution.
  • It affects ColdFusion versions 2025.9, 2023.20, and earlier.
  • Adobe released patches on Tuesday, urging admins to update within 72 hours.
  • CCCS warned on Thursday that threat actors have begun exploiting the flaw.
  • Shadowserver tracks nearly 800 ColdFusion instances exposed online.

Affected

Vendors
Adobe
Products
Adobe ColdFusion
Geography
Global
CVEs
CVE-2026-48282

What happened

The Canadian Center for Cyber Security (CCCS) warned on Thursday that attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw can be abused by attackers without privileges to gain remote code execution on unpatched systems.

Adobe released security updates on Tuesday to address the vulnerability, stating that it posed a high risk of exploitation and urging administrators to deploy patches immediately. Two days later, CCCS confirmed that exploitation was already underway.

Active exploitation confirmed

CCCS cited open-source reporting indicating CVE-2026-48282 is being exploited and urged administrators to apply the necessary updates without delay.

  • CVE-2026-48282 is a maximum-severity flaw
  • Unauthenticated remote code execution
  • Affects ColdFusion 2025.9, 2023.20, and earlier

Who is affected

ColdFusion is a commercial web application development platform used to build and deploy enterprise-grade websites. The vulnerability affects the following versions:

  • ColdFusion 2025.9 and earlier
  • ColdFusion 2023.20 and earlier

Internet security watchdog Shadowserver tracks nearly 800 Adobe ColdFusion instances exposed online, though there is no information on how many are honeypots or have already been secured against attacks targeting CVE-2026-48282.

  • Nearly 800 ColdFusion instances exposed online (Shadowserver)

Adobe's response

Adobe flagged the update as addressing vulnerabilities that pose a higher risk of being targeted by exploits in the wild, and recommended administrators install it as a priority.

In its bulletin, Adobe advised deploying the fix quickly, noting a suggested window of within 72 hours. The company categorized the flaw among issues with a high risk of exploitation.

Adobe's recent security track record

Last week, Adobe released patches for six maximum-severity flaws across ColdFusion and the Campaign Classic marketing automation platform, all exploitable via low-complexity attacks that do not require user interaction and tagged as high risk of being targeted. At the time, Adobe said it was not aware of any exploits in the wild for those issues.

In early April, Adobe issued emergency updates to fix an Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited in zero-day attacks for at least four months, since December 2025.

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 79 vulnerabilities in Adobe products to its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.

What defenders should do

With exploitation confirmed, administrators running affected ColdFusion versions should prioritize patching, especially for internet-exposed instances.

  1. Identify all ColdFusion instances, including internet-facing servers.
  2. Apply Adobe's security updates for CVE-2026-48282 immediately.
  3. Restrict external access to ColdFusion administration interfaces where possible.
  4. Review logs for signs of exploitation or unauthorized code execution.

Timeline

Apr 14, 2026
Adobe releases patchesAdobe issues security updates for CVE-2026-48282, warning of a high risk of exploitation and urging installation within 72 hours.
Apr 16, 2026
CCCS warns of active exploitationThe Canadian Center for Cyber Security warns that threat actors have begun exploiting CVE-2026-48282, citing open-source reporting.

Impact & actions

An actively exploited, unauthenticated remote code execution flaw in Adobe ColdFusion exposes unpatched enterprise web servers to full compromise.

Security: Full server compromise is possible without privileges or user interaction.

Recommended actions · Immediate urgency

  1. 1Apply Adobe's ColdFusion security updates for CVE-2026-48282 immediately
  2. 2Restrict internet exposure of ColdFusion instances
  3. 3Hunt for indicators of exploitation in server logs

Technical details

CVEs
CVE-2026-48282
Exploitation
Exploited in the wild
Attack vector
Network — unauthenticated, no user interaction required
Affected versions
ColdFusion 2025.9 and earlier, ColdFusion 2023.20 and earlier

Mitigations

  • Apply Adobe's security updates for CVE-2026-48282
  • Restrict external access to ColdFusion administration interfaces

Response

Vendor

Adobe stated that the update resolves vulnerabilities being targeted, or at higher risk of being targeted, by exploits in the wild, and recommended administrators install the update as soon as possible (for example, within 72 hours).

Authorities

The CCCS said open-source reporting indicates CVE-2026-48282 is being exploited and encouraged users and administrators to review the provided web links and apply the necessary updates.

Customer guidance

Administrators should deploy Adobe's ColdFusion patches immediately, prioritizing internet-facing instances.

FAQ

What is CVE-2026-48282?

It is a maximum-severity vulnerability in Adobe ColdFusion that allows unauthenticated attackers to gain remote code execution on unpatched systems.

Which ColdFusion versions are affected?

ColdFusion versions 2025.9, 2023.20, and earlier are affected.

Is CVE-2026-48282 being exploited?

Yes. The Canadian Center for Cyber Security warned that threat actors have begun exploiting the flaw, citing open-source reporting.

How should administrators respond?

Adobe recommends installing the security update as soon as possible, ideally within 72 hours, and prioritizing internet-exposed ColdFusion instances.

The bottom line

Adobe patched a maximum-severity ColdFusion RCE flaw, CVE-2026-48282, on Tuesday, and by Thursday the CCCS confirmed attackers were already exploiting it.

What happens next

Given active exploitation and nearly 800 exposed instances, further attacks are likely against unpatched servers; watch for additional advisories and potential CISA catalog listing.

What to do

Apply Adobe's ColdFusion security updates now, prioritizing internet-facing systems.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles