CVE-2026-48282

● KEV CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code exe...

Affects 0 products across 1 vendor.

CVSS 3.110.0
EPSS99.2%
Percentile100th
PatchUnknown
KEV Added2026-07-07
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical severity vulnerability (CVE-2026-48282) affects the target system. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitati...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-48282?
A critical severity vulnerability (CVE-2026-48282) affects the target system. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitati...
What is the CVSS score for CVE-2026-48282?
CVE-2026-48282 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 99.2%.
Is CVE-2026-48282 actively exploited?
Yes. CVE-2026-48282 is in the CISA KEV catalog (added 2026-07-07). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-48282?
Apply vendor patches for CVE-2026-48282. Monitor Adobe advisories.
What systems are affected by CVE-2026-48282?
CVE-2026-48282 affects: Adobe.
Vulnerability Details
CVE IDCVE-2026-48282
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-06-30
Last Modified2026-06-30
Weakness (CWE)
SourceNVD
Official Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Adobe —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 33 Days
CISA KEV● Active Exploitation Confirmed (added 2026-07-07)
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Adobe
CVE-2009-3959 10.0 Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x be... CVE-2026-48281 10.0 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper I... CVE-2015-8402 10.0 Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x... CVE-2010-2217 10.0 Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows a... CVE-2013-3324 10.0 Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows...
View all Adobe CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-48282 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →