CVE-2026-48282 (CVSS 10.0): Adobe ColdFusion RDS Path Traversal Exploited Within 2 Hours of Disclosure, ~800 Internet-Facing Instances Exposed
A maximum-severity path traversal flaw in Adobe ColdFusion's Remote Development Services (RDS) FILEIO handler — enabling unauthenticated arbitrary file write and RCE — was captured in active exploitation by KEVIntel's global honeypot network within under two hours of watchTowr's technical analysis going public on July 2. The Canadian Centre for Cyber Security (CCCS) has independently confirmed in-the-wild exploitation; Adobe's own advisory has not yet been updated to acknowledge it, creating a dangerous guidance gap. Shadowserver tracks roughly 800 internet-facing ColdFusion instances; admins should immediately upgrade to ColdFusion 2025 Update 10 or 2023 Update 21, disable RDS if not required, and hunt for unauthorized files in the web root and /CFIDE/ directories.
The Canadian Centre for Cyber Security (CCCS) has independently confirmed in-the-wild exploitation; Adobe's own advisory has not yet been updated to acknowledge it, creating a dangerous guidance gap.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.