Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. The flaw allows unauthenticated attackers to gain remote code execution on unpatched systems, and Adobe released security updates addressing it earlier in the week.
With ColdFusion widely deployed for enterprise web applications and nearly 800 instances exposed online, an actively exploited unauthenticated RCE flaw creates immediate risk for organizations that have not yet applied Adobe's patches.
Key takeaways
- CVE-2026-48282 is a maximum-severity Adobe ColdFusion flaw enabling unauthenticated remote code execution.
- It affects ColdFusion versions 2025.9, 2023.20, and earlier.
- Adobe released patches on Tuesday, urging admins to update within 72 hours.
- CCCS warned on Thursday that threat actors have begun exploiting the flaw.
- Shadowserver tracks nearly 800 ColdFusion instances exposed online.
Affected
What happened
The Canadian Center for Cyber Security (CCCS) warned on Thursday that attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw can be abused by attackers without privileges to gain remote code execution on unpatched systems.
Adobe released security updates on Tuesday to address the vulnerability, stating that it posed a high risk of exploitation and urging administrators to deploy patches immediately. Two days later, CCCS confirmed that exploitation was already underway.
Active exploitation confirmed
CCCS cited open-source reporting indicating CVE-2026-48282 is being exploited and urged administrators to apply the necessary updates without delay.
- CVE-2026-48282 is a maximum-severity flaw
- Unauthenticated remote code execution
- Affects ColdFusion 2025.9, 2023.20, and earlier
Who is affected
ColdFusion is a commercial web application development platform used to build and deploy enterprise-grade websites. The vulnerability affects the following versions:
- ColdFusion 2025.9 and earlier
- ColdFusion 2023.20 and earlier
Internet security watchdog Shadowserver tracks nearly 800 Adobe ColdFusion instances exposed online, though there is no information on how many are honeypots or have already been secured against attacks targeting CVE-2026-48282.
- Nearly 800 ColdFusion instances exposed online (Shadowserver)
Adobe's response
Adobe flagged the update as addressing vulnerabilities that pose a higher risk of being targeted by exploits in the wild, and recommended administrators install it as a priority.
In its bulletin, Adobe advised deploying the fix quickly, noting a suggested window of within 72 hours. The company categorized the flaw among issues with a high risk of exploitation.
Adobe's recent security track record
Last week, Adobe released patches for six maximum-severity flaws across ColdFusion and the Campaign Classic marketing automation platform, all exploitable via low-complexity attacks that do not require user interaction and tagged as high risk of being targeted. At the time, Adobe said it was not aware of any exploits in the wild for those issues.
In early April, Adobe issued emergency updates to fix an Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited in zero-day attacks for at least four months, since December 2025.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 79 vulnerabilities in Adobe products to its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.
What defenders should do
With exploitation confirmed, administrators running affected ColdFusion versions should prioritize patching, especially for internet-exposed instances.
- Identify all ColdFusion instances, including internet-facing servers.
- Apply Adobe's security updates for CVE-2026-48282 immediately.
- Restrict external access to ColdFusion administration interfaces where possible.
- Review logs for signs of exploitation or unauthorized code execution.
Timeline
Impact & actions
An actively exploited, unauthenticated remote code execution flaw in Adobe ColdFusion exposes unpatched enterprise web servers to full compromise.
Security: Full server compromise is possible without privileges or user interaction.
Recommended actions · Immediate urgency
- 1Apply Adobe's ColdFusion security updates for CVE-2026-48282 immediately
- 2Restrict internet exposure of ColdFusion instances
- 3Hunt for indicators of exploitation in server logs
Technical details
- CVEs
- CVE-2026-48282
- Exploitation
- Exploited in the wild
- Attack vector
- Network — unauthenticated, no user interaction required
- Affected versions
- ColdFusion 2025.9 and earlier, ColdFusion 2023.20 and earlier
Mitigations
- Apply Adobe's security updates for CVE-2026-48282
- Restrict external access to ColdFusion administration interfaces
Response
Vendor
Authorities
Customer guidance
Administrators should deploy Adobe's ColdFusion patches immediately, prioritizing internet-facing instances.
FAQ
What is CVE-2026-48282?
It is a maximum-severity vulnerability in Adobe ColdFusion that allows unauthenticated attackers to gain remote code execution on unpatched systems.
Which ColdFusion versions are affected?
ColdFusion versions 2025.9, 2023.20, and earlier are affected.
Is CVE-2026-48282 being exploited?
Yes. The Canadian Center for Cyber Security warned that threat actors have begun exploiting the flaw, citing open-source reporting.
How should administrators respond?
Adobe recommends installing the security update as soon as possible, ideally within 72 hours, and prioritizing internet-exposed ColdFusion instances.
The bottom line
Adobe patched a maximum-severity ColdFusion RCE flaw, CVE-2026-48282, on Tuesday, and by Thursday the CCCS confirmed attackers were already exploiting it.
What happens next
What to do






