The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal departments to remediate the maximum‑severity CVE‑2026‑48282 ColdFusion vulnerability by Friday, June 10. Adobe issued a patch a week earlier, but threat actors began exploiting the bug within two hours of disclosure.
The United States Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD 26‑04) today, compelling every Federal Civilian Executive Branch (FCEB) agency to apply a security patch for Adobe ColdFusion’s critical flaw CVE‑2026‑48282 no later than Friday, June 10. The vulnerability affects ColdFusion versions 2025.9, 2023.20 and earlier, allowing unauthenticated remote actors to execute arbitrary code with low‑complexity attacks.
Adobe’s swift mitigation
Adobe released a security update a week ago and urged administrators to deploy it within 72 hours, stating, “This update resolves vulnerabilities that are being targeted, or have a higher risk of being targeted, by exploits in the wild.” While Adobe has not confirmed any wild‑type exploits for this specific CVE, the company’s advisory underscores the high exploitation risk.
Attackers move fast
KEVIntel founder Ryan Dewhurst reported that two days after Adobe’s advisory, threat actors were already leveraging CVE‑2026‑48282 in the wild. The Canadian Centre for Cyber Security (CCCS) echoed this urgency, advising network defenders to harden their systems immediately against ongoing attacks.
Shadowserver’s exposure data
Internet‑security watchdog Shadowserver currently tracks roughly 800 publicly exposed Adobe ColdFusion instances. It is unclear how many of these are genuine targets versus honeypots, but the sheer volume highlights the platform’s attractiveness to automated exploit campaigns.
The significance of BOD 26‑04
Published last month, BOD 26‑04 requires agencies to prioritize patching based on four criteria: inclusion in CISA’s KEV catalog, potential for automated large‑scale exploitation, online exposure of vulnerable assets, and the degree of control an exploit grants the attacker. CVE‑2026‑48282 meets all four, earning it top‑priority status.
In the same release window, Adobe also patched six other maximum‑severity flaws across ColdFusion and its Campaign Classic marketing automation platform. Although none have been observed in the wild, the company warned that they present a “high risk of being targeted.” Earlier in April, Adobe issued emergency updates for an Acrobat Reader zero‑day (CVE‑2026‑34621) that had been exploited since December 2025.
Since November 2021, CISA has added 80 Adobe‑related vulnerabilities to its actively exploited list, ten of which have been leveraged in ransomware campaigns. The current directive serves as a stark reminder that rapid patch deployment is essential to prevent escalation from a single code‑execution bug to a nation‑wide security incident.