CVE-2026-48282 is a critical unauthenticated path traversal vulnerability in Adobe ColdFusion's RDS FILEIO handler, exploitable via the /CFIDE/main/ide.cfm?ACTION=FILEIO endpoint. An attacker can send crafted HTTP requests with traversal sequences to read or write arbitrary files on the server, potentially achieving remote code execution by writing malicious .cfm files into web-accessible directories. Adobe has released patches under bulletin APSB26-68 for affected versions (2025.9 and earlier, 2023.20 and earlier).
Path Traversal
5 posts
CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusion It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) Adobe ColdFusion security bulletin APSB26-68 patches 11 CVEs across ColdFusion 2025 and 2023, including critical arbitrary file read/write vulnerabilities in the RDS module and a path traversal in the CKEditor file manager upload endpoint. When RDS is enabled with authentication disabled, attackers can use the simple length-prefixed RDS RPC protocol to read or write arbitrary files, achieving remote code execution as SYSTEM by deploying a CFML webshell. A separate unauthenticated path traversal in the CKEditor file manager allows file uploads to arbitrary directories, also executing as SYSTEM.
Schneider Electric EasyLogic T150 and Saitel DP (CVE-2026-6865) Schneider Electric EasyLogic T150 and Saitel DP Remote Terminal Units are affected by a high-severity Path Traversal vulnerability (CVE-2026-6865, CVSS 7.1). This flaw allows authenticated attackers to access sensitive files on the device due to improper limitation of a pathname to a restricted directory. Firmware updates are available to patch the vulnerability.
April 2026 CVE Landscape In April 2026, 37 high-impact vulnerabilities were actively exploited, heavily impacting enterprise systems and edge infrastructure. Notable exploitation includes the delivery of the Nexcorium botnet via CVE-2024-3721 in TBK DVR devices and complete service takeovers of Nginx UI instances via CVE-2026-33032, a missing authentication flaw.
Cyber Centre Daily Advisory Digest — 2026-04-02 (2 advisories) The Canadian Centre for Cyber Security issued two security advisories. Apple released extensive updates across its operating systems to mitigate vulnerabilities, specifically targeting web attacks from the DarkSword iOS exploit kit. WatchGuard patched an Arbitrary File Write via Path Traversal vulnerability affecting the Fireware Web UI in multiple versions of Fireware OS.