Skip to main content

CVE detail

CVE-2026-48282

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS 10.0 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
22
within the 30d window
Peak daily
6
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • ile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf

    newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM
  • erica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation A Hacker Claims 35 GB of Accenture Source Code. The Company

    newssecurityaffairs.comJul 12, 2026, 4:58 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 9, 2026, 9:29 PM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 9, 2026, 6:11 PM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 8, 2026, 11:09 AM
  • at vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions have been exploited in the wild. Tracked as CVE-2026-48282 (CVSS score of 10/10), the ColdFusion bug was flagged as exploited only days after Adobe rolled out patches for it on June 30. It is a path traversal issue that allows attackers to execute arbitrary code. The Langflow s

    newswww.securityweek.comJul 8, 2026, 10:45 AM
  • Shaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled

    newssecurityaffairs.comJul 8, 2026, 8:38 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 8, 2026, 7:24 AM
  • ed maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. The vulnerability ( CVE-2026-48282 ) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems. Adobe released security

    newswww.bleepingcomputer.comJul 8, 2026, 7:16 AM
  • Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the

    newsthehackernews.comJul 8, 2026, 5:33 AM
  • Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek .

    newswww.securityweek.comJul 7, 2026, 12:38 PM
  • CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cyber

    newswww.helpnetsecurity.comJul 7, 2026, 12:03 PM
  • one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)

    governmentwww.cisa.govJul 7, 2026, 12:00 PM
  • mored Likho APT Campaign | Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks | Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild | Hidden Web Prompts Trick AI Agents Into Sending Money | Seven Bugs in FatFs Put IoT and Embedded Devices at Risk | Bad Epoll Flaw Gives Attackers Root Access on Linux and Android | Medtronic

    newssecurityaffairs.comJul 7, 2026, 8:28 AM
  • Hackers Exploit Maximum Severity Adobe ColdFusion FlawInfosecurity Magazine

    VEs on June 30 in the APSB26-68 bulletin. Six of these were given a CVSS score of 10. Security researchers flagged that CVE-2026-48282 was being targeted within hours of the vulnerability being made public. It’s a path traversal flaw in the popular web app development platform which could lead to arbitrary code execution. Read more on Adobe flaws: New

    newswww.infosecurity-magazine.comJul 7, 2026, 8:20 AM
  • Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that could result in arbitrary code execution without authentication. It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers […]

    newssecurityaffairs.comJul 6, 2026, 7:53 PM
  • Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. [...]

    newswww.bleepingcomputer.comJul 6, 2026, 1:18 PM
  • visory, and repeated here for verbosity, the following vulnerabilities have been resolved: - Arbitrary Code Execution - CVE-2026-48276 - Arbitrary Code Execution - CVE-2026-48277 - Arbitrary Code Execution - CVE-2026-48281 - Arbitrary Code Execution - CVE-2026-48316 - Arbitrary Code Execution - CVE-2026-48282 - Arbitrary Code Execution - CVE-2026-48283

    newslabs.watchtowr.comJul 2, 2026, 4:38 PM
  • Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0). If exploited, the flaws could allow attackers to execute arbitrary code, escalate […]

    newssecurityaffairs.comJul 2, 2026, 9:21 AM
  • Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution.

    newswww.securityweek.comJul 1, 2026, 11:27 AM
  • No excerpt available.

    Mitigationwww.cisa.govJun 30, 2026, 4:16 PM
  • No excerpt available.

    Vendor Advisoryhelpx.adobe.comJun 30, 2026, 4:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-48338

    ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacke…

    CVSS 6.8 · Medium
    1 mention
  • CVE-2026-48319

    ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the cont…

    CVSS 9.1 · Critical
    2 mentions
  • CVE-2026-48318

    ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacke…

    CVSS 9.9 · Critical
    4 mentions
  • CVE-2026-48314

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result i…

    CVSS 6.5 · Medium
    3 mentions
  • CVE-2026-48313

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to…

    CVSS 9.3 · Critical
    6 mentions
  • CVE-2026-47932

    ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result i…

    CVSS 8.8 · High
    1 mention