VulnerabilityBleeping Computer
10.0 — CRITICAL
CISA orders feds to patch max severity ColdFusion flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A maximum-severity vulnerability in Adobe ColdFusion has been actively exploited by remote threat actors, with attackers gaining code execution on unpatched systems without privileges. The US government has ordered agencies to patch the flaw by Friday.
⚙️Technical Details
CVEs
CVE-2026-48282CVE-2026-34621Affected Systems: Adobe ColdFusion versions 2025.9, 2023.20 and earlier
Affected Systems
Adobe ColdFusion versions 2025.9, 2023.20 and earlier
Attack Vectors
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
💥Impact Assessment
Severity: Critical
Who Is at Risk
Government agencies and organizations using Adobe ColdFusion versions 2025.9, 2023.20 and earlier
🛡️Recommended Actions
1Deploy patches for Adobe ColdFusion immediately
2Monitor systems for signs of exploitation and implement intrusion detection and prevention measures
3Secure exposed instances of Adobe ColdFusion online to prevent attacks
📦Affected Products
Adobe ColdfusionAdobe AcrobatAdobe Acrobat DcAdobe Acrobat Reader DcApple MacosMicrosoft WindowsAdobe ColdFusion versions 2025.9, 2023.20 and earlier
🔐NVD Verified DataVERIFIED
CVE-2026-48282 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-22
Affected Products (CPE)
Adobe Coldfusion
CVE-2026-34621 ↗CVSS 8.6 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HWeaknesses
CWE-1321
Affected Products (CPE)
Adobe AcrobatAdobe Acrobat DcAdobe Acrobat Reader DcApple MacosMicrosoft Windows
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
