Adobe Patched a Flaw. Hackers Had It Exploited in Two Hours

Adobe Patched a Flaw. Hackers Had It Exploited in Two Hours

There's "fast," there's "very fast," and then there's whatever speed hackers just achieved with Adobe ColdFusion, they had working exploits in the wild before most IT teams had finished their coffee. Somewhere, a patch management calendar is laughing at us.

From Patch Tuesday to Pwned by Lunch

Adobe patched CVE-2026-48282, a maximum-severity remote code execution flaw in ColdFusion, on July 1, 2026, and urged customers to deploy the fix within 72 hours. Threat actors didn't wait for the deadline, or even the day. According to KEVIntel founder Ryan Dewhurst, exploitation attempts began within two hours of the vulnerability's public disclosure, traced to an India-geolocated IP address.

The flaw is a path traversal bug affecting ColdFusion 2025.9, 2023.20, and earlier, and it lets an attacker achieve remote code execution without any credentials or user interaction. CISA added it to its Known Exploited Vulnerabilities catalog within a week, and Shadowserver was still tracking nearly 800 exposed ColdFusion instances online with unclear patch status.

The 72-Hour Window Was Always a Fantasy

Adobe's own "patch within 72 hours" guidance assumed defenders would have a head start. Instead, attackers reverse-engineered the fix, or read the same technical writeups everyone else did, and had a working exploit before most patch cycles even kicked off a change ticket. That's the uncomfortable trend across 2026: the gap between disclosure and exploitation keeps collapsing toward zero.

Nearly 800 exposed instances sitting online with unknown patch status isn't a hypothetical risk, it's 800 open questions somebody needs to answer today, not next sprint. Legacy enterprise platforms like ColdFusion often run mission-critical stuff nobody wants to touch, which is exactly why they become the stuff attackers love touching first.

A 72-hour patch window used to sound cautious. Now it sounds like showing up to a gunfight with a strongly worded memo.

If "we'll patch it next sprint" is your team's honest patching cadence, it's worth a second look before an attacker makes the decision for you, our free security checklist is a solid place to start.

Source: BleepingComputer