PT-2026-53903 · Adobe · Coldfusion

CVE-2026-48282

·

Published

2026-06-30

·

Updated

2026-07-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions prior to 2025 Update 10 Adobe ColdFusion versions prior to 2023 Update 21
Description Adobe ColdFusion contains a path traversal issue caused by improper limitation of a pathname to a restricted directory. The RDS FILEIO handler at the endpoint '/CFIDE/main/ide.cfm' with the parameter ACTION=FILEIO fails to canonicalize user-supplied paths, allowing traversal sequences or absolute paths to escape the root directory. This enables an unauthenticated remote attacker to read and write arbitrary files on the system, which can be leveraged to upload a CFML webshell and achieve arbitrary code execution in the context of the ColdFusion service account. This issue has been actively exploited in the wild, with approximately 800 servers reported as accessible on the internet.
Recommendations Update Adobe ColdFusion 2025 to Update 10. Update Adobe ColdFusion 2023 to Update 21. Rotate CF admin, database, and service account credentials if anomalous file writes are detected.

Exploit

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09259
CVE-2026-48282

Affected Products

Coldfusion