[UPDATE] [critical] Adobe ColdFusion: Multiple Vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Adobe ColdFusion to execute arbitrary code, gain elevated permissions, bypass security measures, conduct cross-site scripting attacks, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- A remote, anonymous attacker can exploit multiple vulnerabilities in Adobe ColdFusion to execute arbitrary code, gain elevated permissions, bypass security measures, conduct cross-site scripting attacks, manipulate data, or disclose confidential information.
- Who is affected
- Deployments of Adobe ColdFusion are affected.
- Urgency
- Remediation is critical urgency due to the potential for severe exploitation.
- Action
- Apply the latest security updates for Adobe ColdFusion.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ColdFusion
Get an email when a new ColdFusion advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2155
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-482765.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482771.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482812.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-48282Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482831.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-482850.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483070.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483134.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483140.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483151.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 71% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48276 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48277 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48281 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48282 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48283 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48316 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedAdobe security advisory (AV26-647) – Update 2cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerabilitycisa-kev
- criticalCVE-2026-48316: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation v…nvd
- unknownNCSC-2026-0217 [1.00] [M/H] Vulnerabilities fixed in Adobe ColdFusionncsc-nl
- unknownMultiple vulnerabilities in Adobe ColdFusion (July 1, 2026)cert-fr-avis
- criticalCVE-2026-48315: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation v…nvd
- mediumCVE-2026-48314: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pa…nvd
- criticalCVE-2026-48313: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pa…nvd
- highCVE-2026-48307: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripti…nvd
- highCVE-2026-48285: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery …nvd
- criticalCVE-2026-48283: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File…nvd
Recent advisories for Adobe ColdFusion
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0294 [1.00] [M/H] Vulnerabilities patched in Adobe ColdFusionncsc-nl · 2026-08-12
- high[NEW] [high] Adobe ColdFusion: Multiple Vulnerabilitiescert-bund · 2026-08-12
- unknownNCSC-2026-0241 [1.00] [M/H] Vulnerabilities fixed in Adobe ColdFusionncsc-nl · 2026-07-16
- high[NEW] [high] Adobe ColdFusion: Multiple vulnerabilitiescert-bund · 2026-07-15
- criticalexploitedCVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerabilitycisa-kev · 2026-07-07
- unknownNCSC-2026-0217 [1.00] [M/H] Vulnerabilities fixed in Adobe ColdFusionncsc-nl · 2026-07-01
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25