CISA has had enough. The agency ordered all federal civilian agencies to patch a maximum-severity Adobe ColdFusion vulnerability by Friday. The clock is ticking.
The flaw, tracked as CVE-2026-48282, carries a CVSS score of 10.0 — the highest possible. It affects ColdFusion versions 2025.9, 2023.20, and earlier. Remote attackers with no privileges can exploit it in low-complexity attacks to execute code on unpatched systems. No authentication needed.
Adobe released patches a week ago and urged admins to deploy within 72 hours. The warning was justified. Security researcher Ryan Dewhurst spotted active exploitation within two hours of Adobe’s disclosure. The Canadian Centre for Cyber Security also sounded the alarm.
Shadowserver tracks nearly 800 internet-exposed ColdFusion instances. Not all of them are real targets — some are honeypots — but the exposure is there. CISA added this bug to its Known Exploited Vulnerabilities catalog on Tuesday, triggering a mandatory patch deadline under BOD 26-04. That directive, published last month, requires federal agencies to patch KEV-listed flaws faster based on risk factors like internet exposure and automation potential.
This isn’t an isolated incident. Adobe patched six other maximum-severity ColdFusion and Campaign Classic flaws last week. None of those have been confirmed as exploited in the wild yet. But Adobe’s track record speaks for itself — since November 2021, CISA has added 80 Adobe vulnerabilities to its KEV catalog, and 10 have been used in ransomware attacks.
Federal agencies have until July 10. Everyone else should patch yesterday.
