Adobe ColdFusion flaw now under attack, Canada's cyber agency warns
A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

Key points
- Canada's Centre for Cyber Security warned on Thursday that hackers are actively exploiting a critical Adobe ColdFusion flaw tracked as CVE-2026-48282.
- Adobe released a fix on Tuesday and urged administrators to patch within 72 hours.
- The bug lets an attacker run their own code on a vulnerable server without needing a password or any user action.
- Shadowserver counts close to 800 ColdFusion servers reachable from the public internet.
- CISA has added 79 Adobe product flaws to its known-exploited catalogue since November 2021, ten of which appeared in ransomware attacks.
Hackers are already breaking into servers running Adobe ColdFusion, and Canada's national cyber agency is telling defenders to patch now.
ColdFusion is a commercial tool companies use to build business websites and web applications. The flaw, tracked as CVE-2026-48282, affects ColdFusion versions 2025.9, 2023.20 and earlier. It lets an attacker send a booby-trapped request to a vulnerable server and take full control, no login required.
Adobe shipped a patch on Tuesday. Two days later, the Canadian Centre for Cyber Security, the government body that coordinates Canada's response to major cyber incidents, said attacks were already underway and pushed administrators to update.
"Open-source reporting indicates that CVE-2026-48282 is being exploited," the agency said in its advisory.
Adobe's own security bulletin told customers to install the update "as soon as possible (for example, within 72 hours)." That's the language Adobe reserves for flaws it expects criminals to jump on quickly.
Who is actually exploiting it?
Nobody has named a group yet. The Canadian advisory points only to "open-source reporting," and there's no public attribution to a known cluster. That matters. ColdFusion flaws have a history of being picked up by criminal ransomware affiliates and Chinese and Iranian espionage groups within days of disclosure, so capability here is broad even if intent from this specific wave is unclear.
Treat this as medium confidence at best on who is behind it, and high confidence that exploitation is real.
How exposed are companies right now?
Shadowserver, a non-profit that scans the internet for exposed systems, currently sees close to 800 ColdFusion servers reachable from the open web. Some of those will be honeypots (decoy systems set up by researchers), and some will already be patched. The rest are the problem.
Any organisation running ColdFusion should assume its server is on someone's target list today. This vulnerability follows a pattern we've tracked across several platforms recently: the Oracle E-Business Suite payments bug we reported on 30 June was under active attack within a similar window after patching.
Should you worry?
Most readers won't run ColdFusion themselves. But plenty of the websites they use, from local government portals to small business booking systems, are built on it. If you get an email in the coming weeks saying a service you use has had a data breach, take it seriously: change the password and turn on two-factor authentication, the extra code sent to your phone when you log in.
This is the second painful month for Adobe customers. In early April, the company pushed emergency fixes for an Acrobat Reader bug, CVE-2026-34621, exploited as a zero-day (a flaw the vendor didn't know about) for at least four months before discovery. Last week Adobe also patched six other maximum-severity bugs across ColdFusion and its Campaign Classic marketing product, though it says none of those are being attacked yet.
CISA has added 79 Adobe flaws to its known-exploited list since November 2021. Ten have shown up in ransomware attacks, where criminals lock a company's files and demand payment to restore access.
ColdFusion is a repeat target with a well-worn exploitation timeline. The 72-hour window Adobe suggested has already closed.



