DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
CRITICAL#zero day

CVE-2026-48282 (CVSS 10.0): Adobe ColdFusion RDS Path Traversal Exploited Within 2 Hours of Disclosure, ~800 Internet-Facing Instances Exposed

A maximum-severity path traversal flaw in Adobe ColdFusion's Remote Development Services (RDS) FILEIO handler — enabling unauthenticated arbitrary file write and RCE — was captured in active exploitation by KEVIntel's global honeypot network within under two hours of watchTowr's technical analysis going public on July 2. The Canadian Centre for Cyber Security (CCCS) has independently confirmed in-the-wild exploitation; Adobe's own advisory has not yet been updated to acknowledge it, creating a dangerous guidance gap. Shadowserver tracks roughly 800 internet-facing ColdFusion instances; admins should immediately upgrade to ColdFusion 2025 Update 10 or 2023 Update 21, disable RDS if not required, and hunt for unauthorized files in the web root and /CFIDE/ directories.

The Canadian Centre for Cyber Security (CCCS) has independently confirmed in-the-wild exploitation; Adobe's own advisory has not yet been updated to acknowledge it, creating a dangerous guidance gap.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn