CVE-2026-48282: A Perfect 10 in Adobe ColdFusion, Exploited Within Two Hours
A CVSS 10.0 path traversal in Adobe ColdFusion's Remote Development Services lets unauthenticated attackers write a webshell straight into the web root. Attackers were probing it before most admins finished reading the advisory.