Knox CVE Database
/
CVE-2026-48282
Critical
10.0

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Added to the CISA KEV catalog:
July 7, 2026

Overview

Adobe ColdFusion contains a path traversal flaw that allows an unauthenticated remote attacker to read or write files outside the directories ColdFusion is intended to access. By supplying a crafted request with traversal sequences, an attacker can place or overwrite files in locations where ColdFusion will execute them, achieving arbitrary code execution under the ColdFusion service account. ColdFusion 2025 through Update 9 and ColdFusion 2023 through Update 20 are affected. Adobe has confirmed active exploitation in limited attacks targeting this vulnerability.

Vulnerability details

Affected vendor
Adobe
Affected product
ColdFusion
Weakness type (CWE)
CWE-22

Path traversal vulnerabilities (CWE-22) arise when an application accepts user-supplied file path input and fails to canonicalize or restrict it to an intended directory before acting on it. In ColdFusion, the server processes path inputs as part of its file-handling operations. When those inputs contain traversal sequences such as '../' or their encoded equivalents, the server resolves them against the filesystem without enforcing the intended directory boundary. An attacker can direct reads or writes to arbitrary locations on the host, including directories that hold executable content the ColdFusion runtime will later process.


An unauthenticated attacker with network access to a ColdFusion instance sends a crafted HTTP request containing path traversal sequences to a ColdFusion endpoint. No credentials, no prior foothold, and no user interaction are required. The traversal allows the attacker to write a file, such as a web shell or script, into a location where ColdFusion will execute it. Code runs in the context of the ColdFusion service account, and the scope change means the impact extends beyond the ColdFusion process itself to other resources on the host or network. Adobe has confirmed this vulnerability is being exploited in the wild.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review ColdFusion access logs and web server logs for requests containing path traversal patterns ('../', '%2e%2e%2f', '%252e', or similar encoded variants) in file path parameters or URL segments, particularly from sources with no prior authenticated session.
  • Monitor the ColdFusion web root and application directories for new or modified files, especially CFML templates or scripts, created by the ColdFusion service account process outside of normal deployment activity. Unexpected file creation is a strong indicator of write-side exploitation.
  • Alert on ColdFusion service account process activity that spawns child processes (cmd.exe, powershell.exe, sh, bash) or initiates outbound network connections to external hosts, which would indicate post-exploitation code execution.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 10, 2026

Additional hardening

  • Update ColdFusion 2025 to Update 10 and ColdFusion 2023 to Update 21, the fixed releases identified in Adobe security bulletin APSB26-68. Adobe rates these updates Priority 1 given confirmed active exploitation.
  • Restrict network access to ColdFusion administrative interfaces and application endpoints using a web application firewall or network perimeter controls. Limit inbound access to known, trusted source addresses where operationally feasible.
  • Run the ColdFusion service under a least-privilege account with write access restricted to only the directories required for normal operation. This limits the filesystem locations an attacker can reach through a write-side traversal.
  • Review and apply Adobe's serial filter configuration guidance to reduce the attack surface for file-handling and deserialization operations, as referenced in the vendor advisory.

Key dates

Published (NVD)
June 30, 2026
Added to CISA KEV
July 7, 2026
Remediation deadline
July 10, 2026
Last updated
August 27, 2026

References

Frequently asked questions

Does CVE-2026-48282 affect my FedRAMP authorization?

If Adobe ColdFusion runs inside your authorization boundary, CVE-2026-48282 affects your FedRAMP authorization directly. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of July 10, 2026. For any FedRAMP-authorized service, an unpatched KEV within the boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it.

How does Knox help me handle CVE-2026-48282?

Knox does not patch Adobe ColdFusion on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-48282 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to help you document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-48282 class exposures. That means gaps surface during ongoing monitoring rather than only when an assessor reviews your posture at a scheduled assessment. You get earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-48282 isn't remediated by July 10, 2026?

Missing the July 10, 2026 deadline turns CVE-2026-48282 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing intact and the agency relationship straightforward.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting