CVE-2026-48282 is a critical unauthenticated path traversal vulnerability in Adobe ColdFusion's RDS FILEIO handler, exploitable via the /CFIDE/main/ide.cfm?ACTION=FILEIO endpoint. An attacker can send crafted HTTP requests with traversal sequences to read or write arbitrary files on the server, potentially achieving remote code execution by writing malicious .cfm files into web-accessible directories. Adobe has released patches under bulletin APSB26-68 for affected versions (2025.9 and earlier, 2023.20 and earlier).
WAF
4 posts
CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusion CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal A critical SQL injection vulnerability (CVE-2026-9082) in Drupal core allows unauthenticated attackers to exfiltrate sensitive data or bypass authentication. The flaw specifically affects Drupal environments utilizing a PostgreSQL database backend alongside the JSON:API, Views, or Entity autocomplete modules, stemming from the improper sanitization of PHP array keys before they reach the database abstraction layer.
Protecting Publishing: The Real Cost of AI Bots AI fetcher bots are severely impacting the publishing industry by scraping proprietary content in real-time to feed AI chatbots, leading to a drastic reduction in referral traffic and revenue. Organizations are advised to implement advanced bot management and monetization strategies rather than relying solely on default blocking to mitigate infrastructure strain and financial losses.
Build Transformative Security with AI-Powered WAF Detections Akamai has announced the integration of AI-powered WAF detections into its App & API Protector platform. This enhancement leverages machine learning models trained on global traffic to autonomously identify and mitigate sophisticated web attacks, such as evasive SQL injections and parameter pollution, while maintaining human oversight and minimizing false positives.