CISA has ordered U.S. federal agencies to patch CVE-2026-48282, a maximum-severity remote code execution vulnerability in Adobe ColdFusion, by Friday. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and was actively exploited within two hours of Adobe's disclosure last week. Adobe had already urged admins to patch within 72 hours. CISA added the CVE to its Known Exploited Vulnerabilities catalog and invoked Binding Operational Directive BOD 26-04, which mandates prioritized patching for actively exploited flaws. Shadowserver currently tracks nearly 800 ColdFusion instances exposed online. Adobe also patched six other max-severity ColdFusion flaws last week, though none of those have been confirmed exploited in the wild yet.