ColdFusion CVE-2026-48282: Active Exploitation and CISA Deadline for U.S. Federal Agencies Expires Today
The path traversal vulnerability in Adobe ColdFusion was patched on June 30, but attackers began exploiting it within two hours. CISA set July 10 as the federal deadline.