Dettaglio notizia
| Data | 07/07/2026 |
| Titolo | Adobe ColdFusion RDS File-Write Flaw Faces Active Exploitation |
| Contesto | Adobe ColdFusion is facing active exploitation of CVE-2026-48282, a maximum-severity flaw tied to RDS arbitrary file write that can be abused without privileges on unpatched servers. The Canadian Centre for Cyber Security warned that open-source reporting indicates in-the-wild attacks, while Adobe has issued security updates and urged administrators to patch immediately because of the high risk of compromise. Affected releases include ColdFusion 2025.9, 2023.20, and earlier, and internet scanning data from Shadowserver shows nearly 800 ColdFusion instances exposed online, though the number still vulnerable is unclear. Separate reporting on CVE-2026-48276 highlights a closely related ColdFusion attack path in which an unauthenticated attacker uploads a malicious CFML payload through an unrestricted file-upload weakness, writes a web shell into a web-accessible location, and then triggers it with an HTTP request to gain code execution. That issue was described as critical with a CVSS v3.1 score reflecting full impact to confidentiality, integrity, and availability, and its documented root causes included poor filename and extension validation and storing uploads under the web root. Public detection content has also appeared for CVE-2026-48282, underscoring defender focus on identifying exposed and unpatched ColdFusion systems. |
| Fonte | https://mallory.ai/stories/019f3755-ff1e-7e51-886d-1d5833807fe3 |
| Discussione? | Parliamone sul Forum |