MIRAGE
Threat IntelligenceCVEs › CVE-2026-48282

CVE-2026-48282 — exposed on the internet

CVE-2026-48282: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Adobe ColdFusion 2025

Internet exposure observed by OffSeq scans · last 30 days

1
Exposed hosts
10
CVSS
99.2%
EPSS

Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-48282

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor: AdobeCWE-22

OffSeq internet scanning found CVE-2026-48282 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http

Open the live CVE-2026-48282 view →

References