LIVE · cybersecurity feed
Live wire
cisacritical

CISA orders feds to patch max severity ColdFusion flaw by Friday

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a maximum-severity Adobe ColdFusion vulnerability. This flaw is currently being actively exploited and requires patching by Friday.

zeroday.news · 24d ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical vulnerability in Adobe ColdFusion by Friday. This directive, issued under Binding Operational Directive 26-04, targets a flaw designated CVE-2026-48282, which is actively being exploited by malicious actors.

The vulnerability affects Adobe ColdFusion versions 2025.9, 2023.20, and earlier iterations. Threat actors can exploit this flaw remotely, without requiring prior authentication or elevated privileges, and with minimal technical complexity. Successful exploitation can lead to code execution on unpatched systems, granting attackers control.

Adobe released security updates to address this vulnerability approximately one week prior to CISA's order, strongly advising administrators to implement the patches immediately due to a high risk of exploitation. The company stated that the update resolves vulnerabilities that are either currently being targeted or have a heightened risk of being targeted by exploits in the wild for specific product versions and platforms.

Security researchers have observed rapid exploitation of this flaw. Ryan Dewhurst, founder of KEVIntel, reported that attackers began exploiting CVE-2026-48282 within two hours of Adobe's public disclosure. Concurrently, the Canadian Centre for Cyber Security (CCCS) urged network defenders to take measures to protect their systems against these ongoing attacks.

Shadowserver, an internet security watchdog, is currently monitoring nearly 800 Adobe ColdFusion instances accessible online. However, it remains unclear how many of these are decoys (honeypots) or how many have been secured against attacks targeting CVE-2026-48282.

CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, prompting the directive for U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems by Friday, June 10. Binding Operational Directive 26-04, established last month, requires federal agencies to prioritize patching based on factors including inclusion in the KEV catalog, the potential for automated large-scale attacks, the exposure of vulnerable assets online, and the level of control granted to attackers upon successful exploitation.

In addition to the actively exploited flaw, Adobe also addressed six other maximum-severity vulnerabilities in ColdFusion and its Campaign Classic marketing automation platform last week. These vulnerabilities were also flagged as having a high risk of being targeted. However, Adobe has not indicated that these other vulnerabilities are being exploited in the wild, stating it is unaware of any such exploitation.

This incident follows a pattern of vulnerabilities in Adobe products being actively exploited. Since November 2021, CISA has added 80 vulnerabilities in Adobe products to its KEV catalog, with 10 of these having been leveraged in ransomware attacks. Earlier this year, Adobe also issued emergency updates for a critical vulnerability in Acrobat Reader (CVE-2026-34621) that had been exploited as a zero-day since late 2025.

cisaadobecoldfusionvulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.