CVE-2026-48282 — Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
- CVSS
- 9.1 (Critical)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — patch ColdFusion within the next weekend maintenance window; the CFIDE administrator surface is the highest-priority interface to firewall.
- Affected products
- Adobe ColdFusion
Why this one matters to a CAB
ColdFusion has been a KEV regular for years. Path-traversal vulnerabilities in ColdFusion are consistently weaponized against the CFIDE administrator surface, which is exposed on more internet-facing ColdFusion installs than defenders would like. Adobe’s cadence on ColdFusion advisories is roughly quarterly; falling behind is not optional.
Defender’s angle
- Firewall the CFIDE: block
/CFIDE/and/cfusion/CFIDE/from every source that is not the developer VPN range. This is a five-minute change and it removes most of the practical attack surface even without the patch. - Lockdown script: run Adobe’s ColdFusion Lockdown Guide script after the update. Coverage of the guide is measurably lower than it should be in most enterprise ColdFusion estates.
- Application inventory: an unloved ColdFusion app is a common finding — the CAB should ask whether the app should be retired entirely rather than patched forever.
What to bring to CAB
A change record with two exhibits: the ColdFusion update package version, and the CFIDE firewall rule diff. Both must land or the change is incomplete.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.