peter bassill · operator
$ cve CVE-2026-48282 JSON

CVE-2026-48282 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 42.4% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-10.

Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS42.39% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2026-07-10
Public exploitnone known
Published2026-06-30
Last modified2026-08-28

CISA KEV

NameAdobe ColdFusion Path Traversal Vulnerability
Added2026-07-07
Due2026-07-10
Vendor / productAdobe / ColdFusion
Ransomware usenone reported

Affected (1)

VendorProduct
adobecoldfusion

References

→ the Explorer  ·  watch your stack  ·  NVD