bleeping-computer · Crawled Jul 6, 2026
Max severity Adobe ColdFusion flaw now exploited in attacks
Read original article ↗AI Summary
Threat actors are actively exploiting a maximum-severity vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to achieve remote code execution on unpatched systems. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier. Exploitation began within two hours of public disclosure, prompting urgent warnings from KEVIntel and the Canadian Center for Cyber Security. Adobe urges administrators to apply patches immediately to mitigate risk.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.