Critical Adobe ColdFusion Bug With CVSS 10 Already Being Exploited

Attackers are already exploiting a critical Adobe ColdFusion vulnerability — and it doesn’t get worse than this. CVE-2026-48282 carries a CVSS score of 10 out of 10.

The flaw is a path traversal bug that can lead to arbitrary code execution. Adobe patched it on June 30 alongside five other max-severity flaws in ColdFusion 2025 and 2023. Updates 10 and 21 respectively.

Here’s the scary part. According to KEVIntel, hackers started exploiting CVE-2026-48282 within two hours of the public disclosure. Two hours. That’s barely enough time for most orgs to read the advisory, let alone test and deploy a patch across production systems.

KEVIntel founder Ryan Dewhurst confirmed the in-the-wild exploitation was captured through their global honeypot network. The Canadian Centre for Cyber Security also issued a warning.

Adobe initially said it wasn’t aware of any active exploits, but they still gave the update a Priority 1 rating — meaning patch now. Turns out they were right to be worried.

Tuskira’s CEO Piyush Sharma put it well: the decision window has compressed. When exploits hit two hours after disclosure, you can’t rely on traditional patch cycles. You need to know which systems are reachable, which vulnerabilities create attack paths, and what compensating controls you can lean on while you scramble to patch.

If you’re running ColdFusion, stop reading and patch. Right now.

References