The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in real-world attacks. The issue stems from a path traversal weakness that could allow attackers to execute arbitrary code on vulnerable systems. According to CISA, the vulnerability exists due to improper limitation of file path inputs, classified under CWE-22. This flaw enables remote attackers to manipulate file paths and access restricted directories on affected ColdFusion servers. In practical attack scenarios, threat actors can exploit this behavior to upload or execute malicious...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!