Adobe ColdFusion Path Traversal (CVE‑2026‑48282) Added to CISA KEV Catalog
What It Is — CISA has officially added CVE‑2026‑48282, a path‑traversal flaw in Adobe ColdFusion, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. The vulnerability allows an unauthenticated attacker to read arbitrary files on the server, potentially exposing configuration data, credentials, or private business information.
Exploitability — Evidence of live exploitation has been reported to CISA; a public proof‑of‑concept exists. The CVSS base score is 7.8 (High), reflecting the ease of exploitation and the impact on confidentiality and integrity.
Affected Products – Adobe ColdFusion (all supported versions prior to the forthcoming security patch).
Why It Matters for Compliance & Audit Readiness –
- SOC 2 CC6.1 (Vulnerability Management) requires timely identification, risk‑based prioritization, and documented remediation of high‑risk flaws; a KEV listing forces a clear, auditable remediation deadline.
- Continuous control monitoring can automatically capture patch‑deployment evidence, giving auditors a defensible trail that the organization acted on a known‑exploited issue.
- Demonstrating rapid response to a CISA‑designated KEV strengthens third‑party risk assessments and satisfies the “risk‑based remediation” expectations of many enterprise contracts.
Recommended Actions –
- Verify whether any public‑facing assets run Adobe ColdFusion and confirm the version.
- Prioritize patching of CVE‑2026‑48282 in accordance with BOD 26‑04; document the change in your change‑management system.
- Map the remediation to SOC 2 CC6.1 and capture patch‑deployment logs as audit evidence.
- Enable continuous vulnerability scanning to flag future KEV additions automatically.
- Review incident‑response playbooks to ensure detection of post‑exploitation activity before the patch is applied.
Source: CISA Advisory – July 7 2026