bleeping-computer · Crawled Jul 8, 2026
CISA orders feds to patch max severity ColdFusion flaw by Friday
Read original article ↗AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-48282, in Adobe ColdFusion by a strict deadline due to active exploitation in the wild. The flaw allows unauthenticated remote attackers to achieve code execution on unpatched systems with low attack complexity. Adobe released patches one week prior and warned of high exploitation risk, with evidence of attacks emerging within hours of disclosure.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.