CVE-2026-48282 is now being exploited against Adobe ColdFusion, turning Adobe's June 30 patch from routine maintenance into incident triage. Admins should update ColdFusion 2025 and 2023, review logs from the disclosure window, and verify exposed paths are closed.