The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch a critical Adobe ColdFusion vulnerability. The security flaw is identified as CVE-2026-48282. It carries a maximum severity score of 10/10.

Attackers are actively exploiting the bug to execute remote code without privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

Federal Civilian Executive Branch agencies must apply security updates by July 10, 2026. Adobe released the initial patches on June 30. Adobe warns of a high risk of exploitation and urges immediate administrative action.