Adobe ColdFusion: Six CVSS 10.0 RCEs in One Update — CVE-2026-48276, 48277, 48281, 48282, 48283, 48316

Technical analysis of Adobe's emergency bulletin addressing six simultaneous CVSS 10.0 unauthenticated RCE flaws.

Adobe ColdFusion: Six CVSS 10.0 RCEs in One Update — CVE-2026-48276, 48277, 48281, 48282, 48283, 48316

This post is part of the Week of July 3, 2026 Security Roundup.

Overview

On July 1, 2026, Adobe released emergency bulletin APSB26-68 for ColdFusion and Adobe Campaign Classic, addressing eleven vulnerabilities — six at the maximum CVSS score of 10.0, all enabling unauthenticated remote code execution. This is the largest single-release concentration of max-severity flaws in ColdFusion's history.

Affected Versions

  • ColdFusion 2025 ≤ Update 9 → Fixed in Update 10
  • ColdFusion 2023 ≤ Update 20 → Fixed in Update 21
  • Adobe Campaign Classic — multiple versions (see APSB26-69)

CVE Summary

CVECWECVSSImpact
CVE-2026-48276CWE-43410.0Unrestricted file upload → pre-auth RCE
CVE-2026-48283CWE-43410.0Unrestricted file upload → pre-auth RCE
CVE-2026-48277CWE-2010.0Improper input validation → pre-auth RCE
CVE-2026-48281CWE-2010.0Improper input validation → pre-auth RCE
CVE-2026-48316CWE-2010.0Improper input validation → pre-auth RCE
CVE-2026-48282CWE-2210.0Path traversal → pre-auth RCE
CVE-2026-48313CWE-229.3Path traversal → arbitrary file read (pre-auth)
CVE-2026-48315CWE-9188.1Server-side request forgery

Attack Chain — File Upload (CVE-2026-48276, 48283)

The CWE-434 flaws expose ColdFusion file-handling endpoints — including components used by the ColdFusion Builder IDE integration and CFIDE administrative paths — without authentication or file-type validation. An attacker posts a .cfm webshell directly to these endpoints:

POST /CFIDE/scripts/ajax/package/cffileupload.cfm HTTP/1.1
Host: target.example.com
Content-Type: multipart/form-data; boundary=----b

------b
Content-Disposition: form-data; name="file"; filename="shell.cfm"
Content-Type: application/octet-stream

<cfexecute name="/bin/bash" arguments="-c 'id > /tmp/out'" timeout="5"></cfexecute>
------b--

The uploaded file lands in a web-accessible directory and can be requested immediately for execution.

Attack Chain — Input Validation (CVE-2026-48277, 48281, 48316)

ColdFusion's Event Gateway, Scheduler, and built-in service endpoints pass user-supplied parameters to internal shell commands without adequate sanitization. A crafted POST with shell metacharacters in parameter values achieves command injection as the ColdFusion service user (often root or SYSTEM on default installations).

Attack Chain — Path Traversal RCE (CVE-2026-48282)

The CWE-22 RCE flaw resides in ColdFusion's component deployment handler. An unauthenticated request with ../ sequences in the destination path traverses outside the declared upload directory, placing a ColdFusion template into /CFIDE/ or another web-accessible location. A follow-up GET request executes the template.

Exploitation History and Risk Assessment

ColdFusion has an established pattern of rapid weaponization after patch publication:

  • CVE-2023-26360: Patched March 14 — mass exploitation by March 22 (8 days)
  • CVE-2024-20767: Patched March 2024 — PoC within 5 days, exploitation confirmed within 2 weeks

Given six simultaneous CVSS 10.0 pre-auth RCE bugs and significant ColdFusion deployment in government, healthcare, and financial sectors, weaponization should be treated as imminent.

Remediation

# Check ColdFusion version via Admin panel or:
curl -s http://localhost:8500/CFIDE/administrator/index.cfm | grep -i version

# Apply patches via CF Admin:
# Admin Panel → Server Update → Available Updates → Apply Update 10 (CF2025) / Update 21 (CF2023)

# Block CF admin port to trusted IPs only
iptables -I INPUT -p tcp --dport 8500 ! -s 10.0.0.0/8 -j DROP

# Scan for unexpected files in web root (post-exploitation indicators)
find /opt/coldfusion/cfusion/wwwroot -name "*.cfm"   -newer /opt/coldfusion/cfusion/wwwroot/index.cfm -type f -ls
find /opt/coldfusion/cfusion/wwwroot -name "*.jsp" -type f -ls

# Enable ColdFusion Sandbox Security to restrict filesystem access per vdir
# Admin Panel → Security → Sandbox Security → Add Security Sandbox

IOCs

No specific exploitation IOCs confirmed as of July 2, 2026. Monitor for:

  • Unexpected .cfm or .jsp files appearing in ColdFusion web directories
  • Outbound network connections from coldfusion process (Linux) or coldfusion.exe / jvm.exe (Windows) to non-standard destinations
  • Windows Event ID 4688 / Linux auditd execve events where the parent process is the CF JVM spawning shells (cmd.exe, bash, sh)
  • POST requests to /CFIDE/scripts/, /CFIDE/administrator/, or Gateway/Scheduler endpoints from unexpected source IPs

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther