All posts

ColdFusion CVE-2026-48282 Hits KEV at CVSS 10

The Senserva daily security read, July 20, 2026

Adobe ColdFusion CVE-2026-48282 is the one to move on

The top mover today is CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion carrying a CVSS score of 10 and an EPSS of about 0.29. It is on the CISA KEV list, which means it is being actively exploited, not theoretical. If you run ColdFusion anywhere internet-facing, this is a patch-now situation rather than a patch-eventually one.

Right behind it is CVE-2026-34910, an improper input validation flaw in Ubiquiti UniFi OS, also rated CVSS 10 and KEV listed with an EPSS near 0.79. That combination of a perfect severity score and high exploitation probability makes it a priority for anyone running UniFi gear.

More KEV movers to check against your inventory

The exploited list this cycle also includes CVE-2026-55255, a critical authorization bypass in Langflow (CVSS 9.9), and CVE-2007-3010, an Alcatel OmniPCX Enterprise remote code execution flaw (CVSS 9.8) with an EPSS of 0.98, which is about as high as exploitation likelihood gets. Two older Microsoft entries, CVE-2008-4250 and CVE-2012-0151, are on the list as well, so verify legacy Windows systems are not still exposed.

On the Microsoft side, CVE-2026-42897 is an Exchange Server spoofing vulnerability (High severity, CVSS 8.8) that is KEV listed. It maps to Exchange Server 2019 Cumulative Update 14 patching, covered by KB5094144, which carries eight CVEs and is flagged as containing KEV-listed content. If you run Exchange on premises, prioritize that update.

What the press adds on SharePoint and WordPress

Rapid7 and SecurityWeek both report on CVE-2026-58644, an unauthenticated remote code execution vulnerability in Microsoft SharePoint Server that is being exploited in the wild soon after disclosure. If you run on-premises SharePoint, treat this as urgent and confirm you have the vendor fix applied.

WordPress operators have two items to act on. Help Net Security and Rapid7 both cover CVE-2026-63030, a critical remote code execution flaw in WordPress core dubbed wp2shell, along with CVE-2026-60137. Patch WordPress core and audit plugins immediately.

Beyond that, BleepingComputer reports CISA is urging immediate action on actively exploited Fortinet FortiSandbox flaws with a hard federal patch deadline, Dark Reading details Inc ransomware exploiting SonicWall SMA zero-days, and BleepingComputer also covers a new Windows LegacyHive zero-day that grants attackers admin privileges. Each of these is worth checking if you run the affected products.

Do this first

Work top down by exploitation status, not just by CVSS. The KEV-listed items are the ones where waiting has a real cost.

  • Patch Adobe ColdFusion for CVE-2026-48282 and UniFi OS for CVE-2026-34910 today; both are CVSS 10 and KEV listed.
  • Apply the SharePoint fix for CVE-2026-58644 and the WordPress core update for CVE-2026-63030; both are being exploited in the wild.
  • Deploy Exchange update KB5094144 to close CVE-2026-42897 on Exchange Server 2019 CU14.
  • Confirm Fortinet FortiSandbox and SonicWall SMA are patched given the active exploitation and CISA deadline reporting.
  • Check legacy Windows for CVE-2008-4250 and CVE-2012-0151 exposure.

Track your own patch state

To sort these by what actually matters, the free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions like the ColdFusion and UniFi entries daily. If you want to confirm your own Microsoft 365, Intune, Defender, and Entra ID posture, Siemserva offers three free unlimited audits after a one-time registration.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-20.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.