INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Adobe ColdFusion Flaw CVE-2026-48282 Exploited
| 2026-07-08 07:16 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical directive to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday, as required by Binding Operational Directive 26-04. The vulnerability, CVE-2026-48282, affects versions 2025.9 and earlier of the software. CISA has added over 80 vulnerabilities to its list of actively exploited security flaws in Adobe products since November 2021, with some being abused in ransomware attacks. The agency warns that attackers have begun exploiting this vulnerability within two hours of Adobe's disclosure, while encouraging network defenders to secure their systems against ongoing attacks.
Technical Mitigations AI-generated
* Implement a secure patching policy for Adobe ColdFusion instances, including regular updates and monitoring of system logs to detect potential exploitation attempts.
* Conduct vulnerability scanning and penetration testing on all ColdFusion instances before deploying patches to identify any weaknesses or vulnerabilities that may be exploited by attackers.
* Use intrusion detection systems (IDS) and security information and event management (SIEM) solutions to monitor for suspicious activity, alerting administrators when potential threats are detected.
* Regularly review and update the company's Known Exploited Vulnerabilities catalog to ensure it remains accurate and up-to-date with newly discovered vulnerabilities.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Classic
AdobeCampaign Classic
AdobeCampaign ClassicCampaign Classic
CVE-2017-3066CVE-2017-3066
CVE-2026-48283CVE-2026-48283
CVE-2026-48307CVE-2026-48307
CVE-2026-48313CVE-2026-48313
CVE-2026-34621CVE-2026-34621
CVE-2026-48286CVE-2026-48286
CVE-2026-48282CVE-2026-48282
CVE-2026-48276CVE-2026-48276
CVE-2026-48277CVE-2026-48277
CVE-2026-48281CVE-2026-48281
CVE-2026-48316CVE-2026-48316
CVE-2026-48315CVE-2026-48315
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
November 2021
Ransomware groups have been exploiting 80 vulnerabilities in Adobe products since November 2021.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, CISA
has added 80 vulnerabilities in Adobe products
to its list of actively exploited security flaws, 10 of which have also been abused in ransomware attacks.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has included 79 vulnerabilities in Adobe products
in its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.
general_metric
80 vulnerabilities
Since November 2021, CISA
has added 80 vulnerabilities in Adobe products
to its list of actively exploited security flaws, 10 of which have also been abused in ransomware attacks.
general_metric
10 flaws
Since November 2021, CISA
has added 80 vulnerabilities in Adobe products
to its list of actively exploited security flaws, 10 of which have also been abused in ransomware attacks.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has included 79 vulnerabilities in Adobe products
in its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.
general_metric
79 vulnerabilities
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has included 79 vulnerabilities in Adobe products
in its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.
February 2025
Threat actors exploited the Adobe ColdFusion Deserialization Vulnerability CVE-2017-3066 in February 2025.
Click on any entity below to view its context and source!
attribution
KEV
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Adobe ColdFusion Deserialization Vulnerability, tracked as
CVE-2017-3066
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1588.006 - Vulnerabilities
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Adobe ColdFusion Deserialization Vulnerability, tracked as
CVE-2017-3066
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
CVE-2017-3066
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Adobe ColdFusion Deserialization Vulnerability, tracked as
CVE-2017-3066
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
Adobe ColdFusion Deserialization Vulnerability
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Adobe ColdFusion Deserialization Vulnerability, tracked as
CVE-2017-3066
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
Known Exploited
In February 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Adobe ColdFusion Deserialization Vulnerability, tracked as
CVE-2017-3066
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
the Christmas 2025
GreyNoise reported a coordinated campaign exploiting Adobe ColdFusion vulnerabilities in early December 2025.
December 2025
Threat actors exploited an Acrobat Reader vulnerability (CVE-2026-34621) that had been in the wild since December 2025.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-34621
"
In early April, Adobe also
released emergency updates
for an Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited as a zero-day
since December 2025
.
"
In early April, Adobe also
issued emergency updates
to fix an Acrobat Reader vulnerability (CVE-2026-34621) that had been exploited in zero-day attacks for at least four months,
since December 2025
.
2026/06/08
Threat actors exploited a vulnerability in Adobe ColdFusion to target systems.
Click on any entity below to view its context and source!
attribution
KEV
BOD 26-04, which
was published last month
, requires federal agencies to prioritize patching based on whether flaws are included in CISA's KEV catalog, whether their exploitation can be automated for large-scale attacks, whether vulnerable assets are exposed online, and whether successful exploitation grants the attackers partial or total control of the targeted device.
Friday, June 10
Threat actors exploited the Adobe ColdFusion Flaw CVE-2026-48282 in attacks targeting U.S. Federal Civilian Executive Branch agencies on Friday, June 10.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-48282
On Tuesday, CISA
added
CVE-2026-48282 to its
list of vulnerabilities actively exploited in attacks
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems by Friday, June 10, as required by Binding Operational Directive (BOD) 26-04.
attribution
U.S. Federal Civilian Executive Branch
On Tuesday, CISA
added
CVE-2026-48282 to its
list of vulnerabilities actively exploited in attacks
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems by Friday, June 10, as required by Binding Operational Directive (BOD) 26-04.
attribution
FCEB
On Tuesday, CISA
added
CVE-2026-48282 to its
list of vulnerabilities actively exploited in attacks
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems by Friday, June 10, as required by Binding Operational Directive (BOD) 26-04.
general_metric
26 Binding Operational Directive
On Tuesday, CISA
added
CVE-2026-48282 to its
list of vulnerabilities actively exploited in attacks
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems by Friday, June 10, as required by Binding Operational Directive (BOD) 26-04.
2026/06/29
Adobe released patches for six maximum-severity flaws in the ColdFusion web app development and Campaign Classic marketing automation platforms.
Click on any entity below to view its context and source!
campaign
Campaign Classic
Adobe ColdFusion instances exposed online (Adobe)
Last week, Adobe
released patches for six maximum-severity flaws
in the ColdFusion web app development and Campaign Classic marketing automation platforms, all of which are exploitable via low-complexity attacks that don't require user interaction and are tagged as high risk of being targeted.
June 30
Threat actors exploited a vulnerability in Adobe ColdFusion to target APSB26 on June 30.
Click on any entity below to view its context and source!
financial
68 APSB26
The software giant released patches for 11 CVEs on June 30 in the APSB26-68 bulletin.
2026/07/01
Threat actors exploited a vulnerability in Adobe ColdFusion to target Campaign Classic.
Click on any entity below to view its context and source!
campaign
Campaign Classic
Last week, Adobe also
patched six other maximum-severity flaws
in the ColdFusion web app development and Campaign Classic marketing automation platforms, all of which were tagged as high risk of being targeted.
Jul 01, 2026
Threat actors exploited a known vulnerability in Adobe ColdFusion to target affected systems.
July 06
Threat actors exploited a vulnerability in Adobe ColdFusion to target systems.
2026/07/08
Attackers exploited a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, allowing remote code execution on vulnerable servers.
Click on any entity below to view its context and source!
infrastructure
2025.9
The vulnerability (
CVE-2026-48282
) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems.
The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
Six of these critical security flaws (tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect
ColdFusion versions 2025.9, 2023.20 and earlier
, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers to execute code on vulnerable servers.
infrastructure
2023.20
The vulnerability (
CVE-2026-48282
) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems.
The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
Six of these critical security flaws (tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect
ColdFusion versions 2025.9, 2023.20 and earlier
, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers to execute code on vulnerable servers.
organisation
ColdFusion
The vulnerability (
CVE-2026-48282
) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems.
Adobe has urged ColdFusion customers to patch their instances immediately after at least one maximum severity flaw was reported as being exploited by attackers.
ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites.
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic.
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic.
Adobe patches seven max severity ColdFusion, Campaign flaws.
organisation
KEVIntel
"
KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS)
encouraged network defenders
to secure their systems against these ongoing attacks.
KEVIntel researchers reported that Less than two hours after details of CVE-2026-48282 became public, attackers started exploiting it in attacks in the wild.
"
Two days later, KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting CVE-2026-48282 within two hours of Adobe's disclosure.
organisation
Adobe
"
KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS)
encouraged network defenders
to secure their systems against these ongoing attacks.
"
Two days later, KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting CVE-2026-48282 within two hours of Adobe's disclosure.
Adobe has urged ColdFusion customers to patch their instances immediately after at least one maximum severity flaw was reported as being exploited by attackers.
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution
Adobe has released security updates for
ColdFusion
and
Campaign Classic
, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0).
The ColdFusion updates "resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass," Adobe said in an alert released Tuesday.
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.
organisation
CVE-2026
"
KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS)
encouraged network defenders
to secure their systems against these ongoing attacks.
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild.
"
Two days later, KEVIntel founder Ryan Dewhurst warned that threat actors began exploiting CVE-2026-48282 within two hours of Adobe's disclosure.
CVE-2026-48313
(CVSS score of 9.3) – A path traversal flaw that could let attackers read sensitive files.
A path traversal vulnerability that could lead to arbitrary code execution
CVE-2026-48313
(CVSS score: 9.3) - A path traversal vulnerability that could lead to arbitrary file system read
CVE-2026-48315
(CVSs score: 9.3) -
According to Adobe's security advisory, CVE-2026-48286 only affects on-premises Adobe Campaign instances (including fully on-premises deployments and on-premises components in hybrid deployments), as the flaw has already been patched on Adobe-hosted instances.
organisation
the Canadian Center for Cyber Security
"
KEVIntel founder Ryan Dewhurst warned two days after Adobe issued patches that attackers had begun exploiting CVE-2026-48282 within two hours of Adobe's disclosure, while the Canadian Center for Cyber Security (CCCS)
encouraged network defenders
to secure their systems against these ongoing attacks.
organisation
Shadowserver
Internet security watchdog group Shadowserver currently tracks
nearly 800 Adobe ColdFusion instances
exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw.
organisation
Adobe ColdFusion
Internet security watchdog group Shadowserver currently tracks
nearly 800 Adobe ColdFusion instances
exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw.
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers.
"
Internet security watchdog Shadowserver now tracks
nearly 800 Adobe ColdFusion instances
exposed online, but there is no information on how many are honeypots or have been secured against attacks targeting the CVE-2026-48282 flaw.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-48282)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Coldfusion)
organisation
CVE-2026-48282
"Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network,"
Dewhurst said
.
CVE-2026-48282
(CVSS score of 10.0) – A path traversal flaw that could result in arbitrary code execution.
Unrestricted upload of file with dangerous type vulnerabilities that could lead to arbitrary code execution
CVE-2026-48277, CVE-2026-48281, CVE-2026-48316
(CVSS scores: 10.0) - Improper input validation vulnerabilities that could lead to arbitrary code execution
CVE-2026-48282
(CVSS score: 10.0) -
organisation
CCCS
"Open-source reporting indicates that CVE-2026-48282 is being exploited," the CCCS said.
infrastructure
10.0
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution
Adobe has released security updates for
ColdFusion
and
Campaign Classic
, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0).
The company also fixed a critical flaw, tracked as CVE-2026-48286 (CVSS score of 10.0) in Adobe Campaign Classic that could let attackers execute arbitrary code due to an authorization weakness.
organisation
Adobe Campaign
According to Adobe's security advisory, CVE-2026-48286 only affects on-premises Adobe Campaign instances (including fully on-premises deployments and on-premises components in hybrid deployments), as the flaw has already been patched on Adobe-hosted instances.
Adobe noted that CVE-2026-48286 only impacts on-premise Adobe Campaign instances, including fully on-premise deployments and on-premise components in hybrid deployments.
organisation
Adobe Campaign Classic
The company also fixed a critical flaw, tracked as CVE-2026-48286 (CVSS score of 10.0) in Adobe Campaign Classic that could let attackers execute arbitrary code due to an authorization weakness.
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
infrastructure
7.4.3
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
The
Campaign Classic
max severity vulnerability (tracked as CVE-2026-48286) affects versions 7.4.3 build 9396 and earlier and could lead to arbitrary code execution in the current user's context after successful exploitation.
The issue affects on-premises deployments running version 7.4.3 build 9396 and earlier and is fixed in build 9397.
It has been patched in version ACC v7: 7.4.3 build 9397.
infrastructure
Windows
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
infrastructure
Linux
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
organisation
ACC
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
DDoS
In 2023,
threat actors targeted
the platform in crypto-mining, DDoS and other attacks.
organisation
Hackers Exploit Maximum Severity
Hackers Exploit Maximum Severity Adobe ColdFusion Flaw.
organisation
CVSS
Six of these were given a CVSS score of 10.
The
vulnerabilities
are listed below -
CVE-2026-48276, CVE-2026-48283
(CVSS scores: 10.0) -
organisation
IP
KEVIntel founder Ryan Dewhurst reported that the attacks originated from the IP address 103.207.14[.]220 by an attacker located in India.
organisation
Anirudh Anand
Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure have been credited with discovering and reporting CVE-2026-48283, CVE-2026-48313, and CVE-2026-48307.
Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure reported several of the vulnerabilities.
organisation
Matan Sandori
Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure have been credited with discovering and reporting CVE-2026-48283, CVE-2026-48313, and CVE-2026-48307.
Security researchers Anirudh Anand, Matan Sandori, and 2Bsecure reported several of the vulnerabilities.
organisation
Adobe's
"The frontier AI capabilities we are using are also available to attackers, and the window between public vulnerability disclosure and active exploitation is compressing from days to hours," Adobe's Chief Security Officer Aanchal Gupta
said
.
organisation
CSO
Aanchal Gupta, Adobe's Chief Security Officer (CSO), also announced on Thursday that the company will switch to twice-monthly security bulletins to deploy security updates faster.
July 14, 2026
Threat actors exploited a previously unknown vulnerability in Adobe ColdFusion to target systems.
Click on any entity below to view its context and source!
organisation
Adobe Security Bulletins
"Effective July 14, 2026, Adobe is moving from monthly to twice-monthly publication of Adobe Security Bulletins and Advisories on the second and fourth Tuesday of each month,"
Gupta said
.
Tactical Metrics
Metrics
infrastructure
2025.9
Software Version
Click for context!
The vulnerability (
CVE-2026-48282
) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems.
It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers to execute code on vulnerable servers.
The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
…(tracked as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect
ColdFusion versions 2025.9, 2023.20 and earlier
, and can be exploited by attackers without privileges to gain remote code execution on unpatche…
Metrics
infrastructure
2023.20
Software Version
The vulnerability (
CVE-2026-48282
) affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by remote threat actors without privileges in low-complexity attacks to gain code execution on unpatched systems.
It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers to execute code on vulnerable servers.
The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems.
…as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect
ColdFusion versions 2025.9, 2023.20 and earlier
, and can be exploited by attackers without privileges to gain remote code execution on unpatched system…
Metrics
financial
68
Apsb26
The software giant released patches for 11 CVEs on June 30 in the APSB26-68 bulletin.
Metrics
infrastructure
10.0
Software Version
…ion and Campaign Classic that could lead to remote code execution
Adobe has released security updates for
ColdFusion
and
Campaign Classic
, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS score of 10.0).
The company also fixed a critical flaw, tracked as CVE-2026-48286 (CVSS score of 10.0) in Adobe Campaign Classic that could let attackers execute arbitrary code due to an authorization weakness.
Metrics
infrastructure
7.4.3
Software Version
The issue affects on-premises deployments running version 7.4.3 build 9396 and earlier and is fixed in build 9397.
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
It has been patched in version ACC v7: 7.4.3 build 9397.
The
Campaign Classic
max severity vulnerability (tracked as CVE-2026-48286) affects versions 7.4.3 build 9396 and earlier and could lead to arbitrary code execution in the current user's context after successful exploitation.
Metrics
infrastructure
Windows
Affected Product
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
Metrics
infrastructure
Linux
Affected Product
Separately, Adobe has also
shipped
fixes to close out a critical flaw in Adobe Campaign Classic impacting versions ACC v7: 7.4.3 build 9396 and earlier for Windows and Linux that could result in arbitrary code execution.
Intelligence Sources
BleepingComputer
2026-07-08
CISA orders feds to patch max severity ColdFusion flaw by Friday
BleepingComputer
Infosecurity-Magazine
2026-07-07
Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
Infosecurity-Magazine
BleepingComputer
2026-07-01
Adobe patches seven max severity ColdFusion, Campaign flaws
BleepingComputer
The Hacker News
2026-07-01
Security Affairs
2026-07-06
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Security Affairs
Security Affairs
2026-07-02
BleepingComputer
2026-07-06
Max severity Adobe ColdFusion flaw now exploited in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T12:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
ColdFusion
entity
15x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
15x
timeline
Temporal Reference
November 2021
date
12x
vulnerability
Exploited CVE
CVE-2026-48282
cve
4x
tactic
Cyber Operation Type
Ransomware
tactic
4x
infrastructure
Software Version
2025.9
version
2x
general metric
Vulnerabilities
80
vulnerabilities
2x
general metric
Flaws
10
flaws
2x
campaign
Campaign
Campaign Classic
operation
2x
general metric
%
54
%
2x
target region
Target Country
United States
country
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
vulnerability
CVSS Score
10
score
2x
general metric
Update
21
update
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
11 METRICS
industry
Targeted Sector
Government
sector
general metric
Coldfusion Versions
2,026
coldfusion versions
general metric
Coldfusion Instances
800
coldfusion instances
general metric
Binding Operational Directive
26
binding operational directive
general metric
Hours
72
hours
general metric
Bulletin
68
bulletin
financial
Apsb26
68
apsb26
source region
Origin Country
India
country
general metric
Coldfusion
2,023
coldfusion
general metric
Jul
1
jul
general metric
Path Traversal Vulnerability
9
path traversal vulnerability
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.