Skip to main content
Change Risk Intel

CVE-2026-48282 — Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

CVSS
9.1 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — patch ColdFusion within the next weekend maintenance window; the CFIDE administrator surface is the highest-priority interface to firewall.
Affected products
Adobe ColdFusion

Why this one matters to a CAB

ColdFusion has been a KEV regular for years. Path-traversal vulnerabilities in ColdFusion are consistently weaponized against the CFIDE administrator surface, which is exposed on more internet-facing ColdFusion installs than defenders would like. Adobe’s cadence on ColdFusion advisories is roughly quarterly; falling behind is not optional.

Defender’s angle

  • Firewall the CFIDE: block /CFIDE/ and /cfusion/CFIDE/ from every source that is not the developer VPN range. This is a five-minute change and it removes most of the practical attack surface even without the patch.
  • Lockdown script: run Adobe’s ColdFusion Lockdown Guide script after the update. Coverage of the guide is measurably lower than it should be in most enterprise ColdFusion estates.
  • Application inventory: an unloved ColdFusion app is a common finding — the CAB should ask whether the app should be retired entirely rather than patched forever.

What to bring to CAB

A change record with two exhibits: the ColdFusion update package version, and the CFIDE firewall rule diff. Both must land or the change is incomplete.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.