S4E just found a high [ai] pa ssl inspection control
critical·Product Based Web Vulnerabilities·Updated Jul 8, 2026

CVE-2026-48282 Scanner

CVE-2026-48282 Scanner - Path Traversal vulnerability in Adobe ColdFusion

Est. Time~1 minutes
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-48282
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ColdFusionby Adobe
0
Updated Aug 5, 2026View on NVD →
Detail

Adobe ColdFusion is widely used by developers and enterprises for creating internet applications. It's utilized across various industries for its rapid development capabilities and extensive integration features. The software is highly customizable and supports a rich set of functionalities, making it popular for building dynamic websites. Adobe ColdFusion is known for its robust framework and ease of use, attracting developers looking to decrease development time. It is typically deployed on servers responsible for handling web applications and supports both HTTP and HTTPS protocols. Organizations rely on it for building secure, scalable, and cloud-ready applications.

This scanner detects a critical Path Traversal vulnerability in Adobe ColdFusion that could be exploited to achieve remote code execution. Path Traversal vulnerabilities occur when an attacker can manipulate file paths to gain unauthorized access to files and directories. In the presence of this vulnerability, an unauthenticated attacker could leverage it to write arbitrary files on the server with malicious payloads. The vulnerability becomes especially severe if remote code execution is possible by uploading executable scripts or files into executable paths. A successful exploit leaves the server open to compromised security and potential data breaches.

The vulnerable endpoint is associated with the RDS feature in ColdFusion, specifically when the RDS FILEIO WRITE operation is exploited. This endpoint enables attackers to write arbitrary files on the server without authentication. The exploitation can be performed remotely without the need for user interaction, thereby increasing the vulnerability's impact. The vulnerability resides in how ColdFusion handles file directory paths, allowing malicious users to navigate outside intended directories. Attackers can use crafted requests to control file paths, resulting in arbitrary file placement and potential script execution.

If exploited, the Path Traversal vulnerability in Adobe ColdFusion could allow attackers to upload malicious files, potentially executing them to gain control of the server. Unauthorized access to sensitive files may occur, leading to data breaches and exposure of confidential information. The integrity and availability of the server could be compromised, and malicious command execution might disrupt services. This exploit allows attackers to control the server remotely, enabling further dissemination of malware. Successful exploitation can severely damage the trust in an organization's security posture.

REFERENCES

Solution Advice
  • Immediately update Adobe ColdFusion to version 2025 Update 10 or 2023 Update 21 or later.
  • Regularly review and patch ColdFusion installations to include security fixes.
  • Disable or secure the RDS feature unless necessary, ensuring authentication is required.
  • Conduct a thorough security audit to identify potential misconfigurations that might be exploited.
  • Implement network-level protections to restrict unauthorized access to sensitive services.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.