All CVEs
Vulnerability intelligence

CVE-2026-48282

CWE-22

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS Score
10
Critical
EPSS — Exploit Probability
99%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-07
Remediation
Patch available
Federal deadline 2026-07-10
NVD entry Vendor patch PoC / advisory CISA KEV

17 articles across 6 outlets · first covered Jul 2, 2026 · latest Jul 13, 2026

Tracked incidents

Coverage timeline