All posts

Adobe ColdFusion CVE-2026-48282 tops KEV movers with EPSS 0.99

The Senserva daily security read, July 27, 2026

Adobe ColdFusion CVE-2026-48282 is the one to move on first

The most urgent item today is CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion. It carries a CVSS score of 10, it is on the CISA Known Exploited Vulnerabilities list, and its EPSS score is 0.992. That combination is about as clear a signal as you get: attackers are exploiting it, and the model says exploitation is near certain. If you run ColdFusion anywhere, treat this as patch now, not patch eventually.

KEV listing is the practical dividing line. A high CVSS score alone tells you how bad exploitation could be. KEV status tells you it is already happening in the wild, which changes the calendar for your remediation.

SharePoint, Exchange, and the rest of the exploited movers

Microsoft SharePoint remote code execution CVE-2026-50522, CVSS 9.8 and KEV listed with an EPSS of 0.571, remains high on the exploited list and still deserves attention if you have not closed it. Watch it alongside the SharePoint security feature bypass CVE-2026-55040, which shares the 9.8 severity but is not yet KEV listed.

On Exchange, CVE-2026-42897, a spoofing vulnerability rated High at CVSS 8.8, is KEV listed. A companion Exchange elevation of privilege issue, CVE-2026-45504, also CVSS 8.8, is not on KEV yet but should be in the same patch cycle. Rounding out the exploited set are Langflow authorization bypass CVE-2026-55255 (CVSS 9.9, KEV) and two older but still actively exploited entries, the Microsoft Windows buffer overflow CVE-2008-4250 and Alcatel OmniPCX RCE CVE-2007-3010 (EPSS 0.9741). Legacy CVEs stay on KEV because they still work against unpatched systems.

What the press adds: ServiceNow, Zimbra, and Russian phishing

Help Net Security's week in review flagged a ServiceNow pre-auth remote code execution being exploited in the wild and a Hugging Face breach, both worth a look if either sits in your stack.

Separately, Help Net Security reported Russian operators exploiting unpatched Zimbra servers to steal emails, tracked as CVE-2025-66376. If you run Zimbra, verify your patch state directly rather than assuming it is current. Australian agencies, including the ASD and the National Cyber Security Coordinator, also warned of an ongoing Russian phishing campaign, so tighten mail authentication and user reporting while you are in there.

Do this first

Work in KEV order. The exploited items above are the ones with real-world attacker activity behind them.

Check your own state

To confirm where you actually stand on these, the free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and a separate tracker follows non-Microsoft KEV additions like the ColdFusion entry daily. If you want a full read on your own Microsoft 365, Intune, Defender, and Entra ID configuration, Siemserva offers three free unlimited audits after a one-time registration.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-27.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.