cisaregulatorNewsThe Broadside1 min read

CISA puts Adobe ColdFusion CVE-2026-48282 in KEV

The operational burden is asset discovery first, patching second, because KEV only matters where exposed ColdFusion can hand over control.


TL;DR

CISA added CVE-2026-48282, an actively exploited Adobe ColdFusion path traversal vulnerability, to the Known Exploited Vulnerabilities Catalog. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize remediation for KEV-listed CVEs on publicly exposed assets that can grant total control after exploitation. Contractors supporting federal systems should expect the same urgency through prime flowdowns. CISA’s alert does not supply exploit code, detection signatures, or a specific deadline.

CISA’s July 7 addition of CVE-2026-48282 is a small catalog update with a large operational qualifier: the mandate is driven by exposure and control. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize KEV-listed Common Vulnerabilities and Exposures on publicly exposed assets that grant total control after exploitation, and to check whether compromise occurred before patching in the circumstances BOD 26-04 covers.

For practitioners, the first task is not reading another KEV alert. It is proving where Adobe ColdFusion is still reachable from the internet, whether the affected instance permits the level of post-exploitation control CISA describes, and who owns the remediation lane. Prime contractors and support vendors are outside BOD 26-04’s direct scope, but federal systems work rarely stays that tidy. Expect contract flowdowns and agency requests to turn this into a deadline-driven inventory and patch exercise, even where CISA’s alert leaves the exact due date and detection support unsaid.


Published ·Deep Fathom