Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild

2026-07-07T02:51:41Zd514b4673c4af4dae4db6b848f2cd94475398c72a3087174ac919743b5553ec3
AI agentsAdobe ColdFusionAndroidBad EpollCVE-2026-46242CVE-2026-48282FatFsIoTLinux kernelMedtronicShinyHuntersTeamPCPZscaler ThreatLabzcloud credential theftdata breach/notification (3.8M)`,`Kairos`,`data extortion`,`Peg˜data leakagedev tools compromiseexploit in the wildindirect prompt injectionlocal privilege escalationmemory corruptionpath traversalremote code executionrunZerosupply chain compromise

What happened

Security Affairs roundup: attackers are actively exploiting a critical Adobe ColdFusion path‑traversal bug (CVE-2026-48282) that enables unauthenticated remote code execution against unpatched ColdFusion 2025.9, 2023.20 and earlier instances. A separate high‑severity Linux kernel local privilege escalation (Bad Epoll, CVE-2026-46242) allows unprivileged local users to gain root on Linux and Android. runZero disclosed seven vulnerabilities in the FatFs library that put IoT and embedded devices at risk of memory corruption, crashes, and data leaks. Other notable reports: indirect prompt‑injekion

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d514b4673c4af4dae4db6b848f2cd94475398c72a3087174ac919743b5553ec3
Enrichment time
2026-07-07T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.