INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Adobe ColdFusion Flaw CVE-2026-48282 Exploited

| 2026-07-08 07:16 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical directive to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday, as required by Binding Operational Directive 26-04. The vulnerability, CVE-2026-48282, affects versions 2025.9 and earlier of the software. CISA has added over 80 vulnerabilities to its list of actively exploited security flaws in Adobe products since November 2021, with some being abused in ransomware attacks. The agency warns that attackers have begun exploiting this vulnerability within two hours of Adobe's disclosure, while encouraging network defenders to secure their systems against ongoing attacks.
Technical Mitigations AI-generated
* Implement a secure patching policy for Adobe ColdFusion instances, including regular updates and monitoring of system logs to detect potential exploitation attempts. * Conduct vulnerability scanning and penetration testing on all ColdFusion instances before deploying patches to identify any weaknesses or vulnerabilities that may be exploited by attackers. * Use intrusion detection systems (IDS) and security information and event management (SIEM) solutions to monitor for suspicious activity, alerting administrators when potential threats are detected. * Regularly review and update the company's Known Exploited Vulnerabilities catalog to ensure it remains accurate and up-to-date with newly discovered vulnerabilities.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Classic AdobeCampaign Classic AdobeCampaign ClassicCampaign Classic CVE-2017-3066CVE-2017-3066 CVE-2026-48283CVE-2026-48283 CVE-2026-48307CVE-2026-48307 CVE-2026-48313CVE-2026-48313 CVE-2026-34621CVE-2026-34621 CVE-2026-48286CVE-2026-48286 CVE-2026-48282CVE-2026-48282 CVE-2026-48276CVE-2026-48276 CVE-2026-48277CVE-2026-48277 CVE-2026-48281CVE-2026-48281 CVE-2026-48316CVE-2026-48316 CVE-2026-48315CVE-2026-48315
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎November 2021
Ransomware groups have been exploiting 80 vulnerabilities in Adobe products since November 2021.
tactic Ransomware
general_metric 80 vulnerabilities
general_metric 10 flaws
general_metric 79 vulnerabilities
‎February 2025
Threat actors exploited the Adobe ColdFusion Deserialization Vulnerability CVE-2017-3066 in February 2025.
attribution KEV
tactic T1588.006 - Vulnerabilities
attribution CVE-2017-3066
attribution Adobe ColdFusion Deserialization Vulnerability
attribution Known Exploited
‎the Christmas 2025
GreyNoise reported a coordinated campaign exploiting Adobe ColdFusion vulnerabilities in early December 2025.
‎December 2025
Threat actors exploited an Acrobat Reader vulnerability (CVE-2026-34621) that had been in the wild since December 2025.
vulnerability CVE-2026-34621
‎2026/06/08
Threat actors exploited a vulnerability in Adobe ColdFusion to target systems.
attribution KEV
‎Friday, June 10
Threat actors exploited the Adobe ColdFusion Flaw CVE-2026-48282 in attacks targeting U.S. Federal Civilian Executive Branch agencies on Friday, June 10.
vulnerability CVE-2026-48282
attribution U.S. Federal Civilian Executive Branch
attribution FCEB
general_metric 26 Binding Operational Directive
‎2026/06/29
Adobe released patches for six maximum-severity flaws in the ColdFusion web app development and Campaign Classic marketing automation platforms.
campaign Campaign Classic
‎June 30
Threat actors exploited a vulnerability in Adobe ColdFusion to target APSB26 on June 30.
financial 68 APSB26
‎2026/07/01
Threat actors exploited a vulnerability in Adobe ColdFusion to target Campaign Classic.
campaign Campaign Classic
‎Jul 01, 2026
Threat actors exploited a known vulnerability in Adobe ColdFusion to target affected systems.
‎July 06
Threat actors exploited a vulnerability in Adobe ColdFusion to target systems.
‎2026/07/08
Attackers exploited a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, allowing remote code execution on vulnerable servers.
infrastructure 2025.9
infrastructure 2023.20
organisation ColdFusion
organisation KEVIntel
organisation Adobe
organisation CVE-2026
organisation the Canadian Center for Cyber Security
organisation Shadowserver
organisation Adobe ColdFusion
organisation SecurityAffairs
organisation CVE-2026-48282
organisation CCCS
infrastructure 10.0
organisation Adobe Campaign
organisation Adobe Campaign Classic
infrastructure 7.4.3
infrastructure Windows
infrastructure Linux
organisation ACC
organisation EDR
organisation DDoS
organisation Hackers Exploit Maximum Severity
organisation CVSS
organisation IP
organisation Anirudh Anand
organisation Matan Sandori
organisation Adobe's
organisation CSO
‎July 14, 2026
Threat actors exploited a previously unknown vulnerability in Adobe ColdFusion to target systems.
organisation Adobe Security Bulletins
Tactical Metrics
Metrics
infrastructure
‎2025.9
Software Version
Metrics
infrastructure
‎2023.20
Software Version
Metrics
financial
68
Apsb26
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎7.4.3
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources
BleepingComputer 2026-07-08
Infosecurity-Magazine 2026-07-07
BleepingComputer 2026-07-01
Security Affairs 2026-07-06
BleepingComputer 2026-07-06