July 8, 2026
- The Adobe ColdFusion exploitation story widened: Horizon3 detailed pre-auth unrestricted file upload and path traversal in CVE-2026-48283/CVE-2026-48313, and a public PoC dropped for the actively exploited CVE-2026-48282 (RDS path traversal, CVSS 10.0). Horizon3, PoC · Vulnerabilities & Exploits
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM