VULNERABILITY OVERVIEW
A path traversal flaw in ColdFusion's Remote Development Services (RDS) FILEIO handler allows unauthenticated remote attackers to read arbitrary files and write PHP/CFML webshells to web-accessible directories, achieving full RCE as NT AUTHORITY\SYSTEM on Windows. KEVIntel honeypots captured in-the-wild exploitation within two hours of WatchTowr's public technical write-up on July 6; Shadowserver tracks ~750 internet-facing ColdFusion instances. CISA added to KEV on July 7 with a federal patch deadline of July 10; patch to ColdFusion 2023 Update 21 or 2025 Update 10 (APSB26-68) is mandatory.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
ColdFusion 2025 Update 9 and earlier; ColdFusion 2023 Update 20 and earlierCITATIONS
- → https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
- → https://www.helpnetsecurity.com/2026/07/07/adobe-coldfusion-cve-2026-48282-exploitation-detected/
- → https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
- → https://orca.security/resources/blog/adobe-coldfusion-rce-flaw-cve-2026-48282/
- → https://www.securityweek.com/critical-adobe-coldfusion-vulnerability-exploited-in-attacks/