LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog on Jul 7, 2026, with a federal patch deadline of Jul 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Adobe ColdFusion contains a path traversal vulnerability that could allow an attacker to access files and execute code in the context of the current user. This matters because ColdFusion often runs web applications that handle sensitive data and business logic, and successful exploitation can lead to unauthorized access without requiring elevated privileges.

How it works

The weakness is classified as CWE-22, a path traversal flaw. An attacker supplies crafted input containing directory traversal sequences to cause the application to access files or resources outside the intended directory scope. In this product class the result can be reading or writing files that enable arbitrary code execution under the permissions of the ColdFusion process.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor update named in the advisory as the primary remediation. After patching, review and restrict file-system permissions for the ColdFusion service account, disable unnecessary features that process external paths, and enforce input validation on any custom code that handles file names or paths.

If you can't patch immediately

If your data may have been exposed

Path traversal vulnerabilities that reach arbitrary code execution can result in data breaches. Stakeholders should evaluate each asset’s internet exposure and run a free exposure scan of organizational email addresses against known breach data to determine whether credentials or other information have already appeared in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · ColdFusion
WeaknessCWE-22
Added to CISA KEVJul 7, 2026
Federal patch deadlineJul 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities