---
title: "CISA orders feds to patch max severity ColdFusion flaw by Friday"
url: https://daily.dev/posts/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday-nsiln2fjk
source_url: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday
type: article
source: "BleepingComputer"
published: 2026-07-08T07:21:26.363Z
updated: 2026-07-08T07:21:55.310Z
tags: ["security"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA orders feds to patch max severity ColdFusion flaw by Friday

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

CISA has ordered U.S. federal agencies to patch CVE-2026-48282, a maximum-severity remote code execution vulnerability in Adobe ColdFusion, by Friday. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and was actively exploited within two hours of Adobe's disclosure last week. Adobe had already urged admins to patch within 72 hours. CISA added the CVE to its Known Exploited Vulnerabilities catalog and invoked Binding Operational Directive BOD 26-04, which mandates prioritized patching for actively exploited flaws. Shadowserver currently tracks nearly 800 ColdFusion instances exposed online. Adobe also patched six other max-severity ColdFusion flaws last week, though none of those have been confirmed exploited in the wild yet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday>

## Similar posts on daily.dev

- [Max severity Adobe ColdFusion flaw now exploited in attacks](https://daily.dev/posts/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks-6xrtvpmdk) · BleepingComputer · 0 upvotes · 0 comments
- [Adobe patches seven max severity ColdFusion, Campaign flaws](https://daily.dev/posts/adobe-patches-seven-max-severity-coldfusion-campaign-flaws-s72osmefg) · BleepingComputer · 1 upvotes · 1 comments
- [Adobe ColdFusion Vulnerabilities Are a Design Failure, Not Bad Luck](https://daily.dev/posts/adobe-coldfusion-vulnerabilities-are-a-design-failure-not-bad-luck-cqajsu8z3) · Latest Hacking News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday-nsiln2fjk)
