Adobe
Vulnerabilities in Adobe ColdFusion, Commerce (Magento), Reader, and Acrobat — a product line whose enterprise footprint keeps it in the KEV catalog and in attacker toolkits well past its perceived relevance.
Adobe ColdFusion path traversal
Path-traversal vulnerability in Adobe ColdFusion that could result in arbitrary code execution. The highest-scored CVE in Adobe's July 2026 ColdFusion cluster. Fixed in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
Adobe ColdFusion path-traversal to arbitrary code execution
Unauthenticated path-traversal (CWE-22) in Adobe ColdFusion 2023 (through update 20) and 2025 (through update 9) permitting arbitrary code execution without user interaction. CVSS 10.0. Patched by Adobe on 2026-07-01 in APSB26-68 (ColdFusion 2023 update 21, 2025 update 10). Active in-the-wild exploitation confirmed by the Canadian Centre for Cyber Security on 2026-07-02; Shadowserver counts ~800 exposed instances.

CISA: Patch ColdFusion CVE-2026-48282 by Friday
CISA added Adobe ColdFusion CVE-2026-48282 to KEV on July 7 and set a July 10 federal patch deadline under BOD 26-04. CVSS 10.0. Actively exploited.

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.