Adobe ColdFusion: Six CVSS 10.0 RCEs in One Update — CVE-2026-48276, 48277, 48281, 48282, 48283, 48316
Technical analysis of Adobe's emergency bulletin addressing six simultaneous CVSS 10.0 unauthenticated RCE flaws.
This post is part of the Week of July 3, 2026 Security Roundup.
Overview
On July 1, 2026, Adobe released emergency bulletin APSB26-68 for ColdFusion and Adobe Campaign Classic, addressing eleven vulnerabilities — six at the maximum CVSS score of 10.0, all enabling unauthenticated remote code execution. This is the largest single-release concentration of max-severity flaws in ColdFusion's history.
Affected Versions
- ColdFusion 2025 ≤ Update 9 → Fixed in Update 10
- ColdFusion 2023 ≤ Update 20 → Fixed in Update 21
- Adobe Campaign Classic — multiple versions (see APSB26-69)
CVE Summary
| CVE | CWE | CVSS | Impact |
|---|---|---|---|
| CVE-2026-48276 | CWE-434 | 10.0 | Unrestricted file upload → pre-auth RCE |
| CVE-2026-48283 | CWE-434 | 10.0 | Unrestricted file upload → pre-auth RCE |
| CVE-2026-48277 | CWE-20 | 10.0 | Improper input validation → pre-auth RCE |
| CVE-2026-48281 | CWE-20 | 10.0 | Improper input validation → pre-auth RCE |
| CVE-2026-48316 | CWE-20 | 10.0 | Improper input validation → pre-auth RCE |
| CVE-2026-48282 | CWE-22 | 10.0 | Path traversal → pre-auth RCE |
| CVE-2026-48313 | CWE-22 | 9.3 | Path traversal → arbitrary file read (pre-auth) |
| CVE-2026-48315 | CWE-918 | 8.1 | Server-side request forgery |
Attack Chain — File Upload (CVE-2026-48276, 48283)
The CWE-434 flaws expose ColdFusion file-handling endpoints — including components used by the ColdFusion Builder IDE integration and CFIDE administrative paths — without authentication or file-type validation. An attacker posts a .cfm webshell directly to these endpoints:
POST /CFIDE/scripts/ajax/package/cffileupload.cfm HTTP/1.1
Host: target.example.com
Content-Type: multipart/form-data; boundary=----b
------b
Content-Disposition: form-data; name="file"; filename="shell.cfm"
Content-Type: application/octet-stream
<cfexecute name="/bin/bash" arguments="-c 'id > /tmp/out'" timeout="5"></cfexecute>
------b--
The uploaded file lands in a web-accessible directory and can be requested immediately for execution.
Attack Chain — Input Validation (CVE-2026-48277, 48281, 48316)
ColdFusion's Event Gateway, Scheduler, and built-in service endpoints pass user-supplied parameters to internal shell commands without adequate sanitization. A crafted POST with shell metacharacters in parameter values achieves command injection as the ColdFusion service user (often root or SYSTEM on default installations).
Attack Chain — Path Traversal RCE (CVE-2026-48282)
The CWE-22 RCE flaw resides in ColdFusion's component deployment handler. An unauthenticated request with ../ sequences in the destination path traverses outside the declared upload directory, placing a ColdFusion template into /CFIDE/ or another web-accessible location. A follow-up GET request executes the template.
Exploitation History and Risk Assessment
ColdFusion has an established pattern of rapid weaponization after patch publication:
- CVE-2023-26360: Patched March 14 — mass exploitation by March 22 (8 days)
- CVE-2024-20767: Patched March 2024 — PoC within 5 days, exploitation confirmed within 2 weeks
Given six simultaneous CVSS 10.0 pre-auth RCE bugs and significant ColdFusion deployment in government, healthcare, and financial sectors, weaponization should be treated as imminent.
Remediation
# Check ColdFusion version via Admin panel or:
curl -s http://localhost:8500/CFIDE/administrator/index.cfm | grep -i version
# Apply patches via CF Admin:
# Admin Panel → Server Update → Available Updates → Apply Update 10 (CF2025) / Update 21 (CF2023)
# Block CF admin port to trusted IPs only
iptables -I INPUT -p tcp --dport 8500 ! -s 10.0.0.0/8 -j DROP
# Scan for unexpected files in web root (post-exploitation indicators)
find /opt/coldfusion/cfusion/wwwroot -name "*.cfm" -newer /opt/coldfusion/cfusion/wwwroot/index.cfm -type f -ls
find /opt/coldfusion/cfusion/wwwroot -name "*.jsp" -type f -ls
# Enable ColdFusion Sandbox Security to restrict filesystem access per vdir
# Admin Panel → Security → Sandbox Security → Add Security Sandbox
IOCs
No specific exploitation IOCs confirmed as of July 2, 2026. Monitor for:
- Unexpected
.cfmor.jspfiles appearing in ColdFusion web directories - Outbound network connections from
coldfusionprocess (Linux) orcoldfusion.exe/jvm.exe(Windows) to non-standard destinations - Windows Event ID 4688 / Linux
auditd execveevents where the parent process is the CF JVM spawning shells (cmd.exe,bash,sh) - POST requests to
/CFIDE/scripts/,/CFIDE/administrator/, or Gateway/Scheduler endpoints from unexpected source IPs