Adobe ColdFusion CVE-2026-48282: a max-severity RCE exploited within 2 hours of disclosure
> In short: CVE-2026-48282 is a maximum-severity unauthenticated remote code execution flaw in Adobe ColdFusion (versions 2025.9, 2023.20, and earlier). CVSS 9.8, no privileges required. Exploitation started within 2 hours of Adobe's disclosure on July 1, 2026, per KEVIntel's honeypot network. Shadowserver tracks ~800 ColdFusion instances exposed online.
Why this still matters in 2026
ColdFusion is the legacy web platform people love to declare dead — and that keeps running mission-critical government, legal, and enterprise portals. If you sell to the French public sector, legaltech, or large enterprises, your clients' intranet, document portal, or legacy module is disproportionately likely to sit on ColdFusion. The platform's persistence is exactly what makes it a target: large attack surface, slow patching cadence, valuable data behind it.
The flaw and the timeline
Adobe disclosed CVE-2026-48282 on July 1 as part of a batch of six maximum-severity ColdFusion/Campaign flaws. The bulletin described it as a high-risk-of-exploitation RCE achievable with low complexity and no user interaction. Adobe's standard recommendation: install within 72 hours.
The reality was faster. KEVIntel captured in-the-wild exploitation within *under two hours* of the public details going out. The Canadian Centre for Cyber Security (CCCS) issued an alert confirming active exploitation. This is the modern disclosure-to-exploitation curve: when a max-severity web-RCE drops, you measure the safe window in hours, not days.
The ColdFusion pattern
ColdFusion has been a recurrent CISA KEV occupant. Since November 2021, 79 Adobe product CVEs have made it into the catalog of actively exploited flaws, and 10 of those have been used in ransomware attacks. ColdFusion RCE flaws specifically have a history of mass scanning within 24-48 hours of disclosure. The reasons are structural:
When all three line up, you get the "2-hour" exploitation window we saw here.
What to do
The SaaS angle
For a SaaS vendor, ColdFusion usually shows up in two places: in your clients' legacy stack (which becomes your problem when you integrate with it), and occasionally in an acquired legacy product you're still maintaining. Either way, the lesson from CVE-2026-48282 is operational: any web platform with a history of unauthenticated RCE and an active scanner ecosystem must be on a sub-72-hour patch SLA, behind a gateway, and off the public internet. "We'll patch next month" is not a posture that survives the 2-hour window.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Adobe Campaign Classic CVE-2026-48449: a perfect 10.0 RCE in enterprise marketing
A maximum-severity authorization flaw (CVSS 10.0) in Adobe Campaign Classic allows arbitrary code execution without user interaction. Paired with CVE-2026-48448 (SQL injection, 8.6) allowing arbitrary file reads. Fixed in ACC v7 build 9398. Not yet exploited.
Fastjson 1.x CVE-2026-16723: a critical RCE with no patch, actively exploited
A CVSS 9.0 remote code execution flaw in Alibaba's Fastjson 1.2.68–1.2.83 lets an unauthenticated attacker run code on affected Spring Boot fat-JAR applications. No AutoType or classpath gadget required. No 1.x patch exists yet. Workaround: SafeMode.
Rails Active Storage: a critical flaw with arbitrary file read and RCE potential
A critical vulnerability in the Rails Active Storage framework lets an unauthenticated attacker read arbitrary files from the application server, with potential escalation to remote code execution. Affects Ruby on Rails applications using Active Storage. Patch now available.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.