CVE-2026-48282
Summary
A path-traversal vulnerability in Adobe ColdFusion, scored CVSS 10.0, added to CISA's Known Exploited Vulnerabilities catalog on 7 July 2026 on evidence of active exploitation.
Details
ColdFusion is a long-standing favourite of initial-access brokers and web-shell operators — the same platform has carried repeated exploited flaws across the 2023–2026 period — because it is internet-facing by design, frequently unmanaged by the team that owns the surrounding application, and runs with enough privilege to write into the web root. A traversal flaw at maximum severity is the classic precursor to dropping a shell. The digest recorded it as one of four vulnerabilities in the 7 July KEV batch, alongside Langflow's authorisation bypass (CVE-2026-55255) and two Joomla extension flaws.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-48282 |
| CVSS | 10.0 |
| Vendor / product | Adobe (ColdFusion) |
| Reported in the digest | 2026-07-09 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-09.md