releases.shpreview

Adobe ColdFusion and WordPress CVEs blocked; SSRF, LFI rules upgraded

16 featuresThis release16 featuresNew capabilitiesAI-tallied from the release notes
From the original release noteView original ↗

This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Adobe ColdFusion and WordPress, alongside enhanced generic protections against enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) obfuscation techniques. To strengthen overall detection capabilities across emerging threat vectors, new emergency detection rules have also been deployed for Generic Rules - Unauthenticated Remote Code Execution (RCE), Generic Rules - Authentication Bypass (Auth Bypass - 2) and Generic Rules - Information Disclosure.

Key Findings

  • CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.

  • CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.

  • CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.

  • CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...215e7d31

N/A

SSRF - Restricted Protocol

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...a935ee5d

N/A

SSRF - Obfuscated Host

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...1b0230ac

N/A

LFI - Path Traversal

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...61349c8b

N/A

Adobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...9cb61eac

N/A

Adobe ColdFusion - Path Traversal - CVE:CVE-2026-48282

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...4ac5e21f

N/A

XSS — JS Bracket Concat Obfuscation - Body

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...f31f5559

N/A

XSS — JS Bracket Concat Obfuscation - Headers

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...987984fd

N/A

XSS — JS Bracket Concat Obfuscation - URI

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...ed933fcc

N/A

Wordpress - SQL Injection - CVE:CVE-2026-60137

N/A

Block

This was labeled as Generic Rules - SQLi.

Cloudflare Managed Ruleset

...550664b6

N/A

Wordpress - Remote Code Execution - CVE:CVE-2026-63030

N/A

Block

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Free Ruleset

...33697a1a

N/A

Wordpress - SQL Injection - CVE:CVE-2026-60137

N/A

Block

This was labeled as Generic Rules - SQLi.

Cloudflare Free Ruleset

...b5ec246a

N/A

Wordpress - Remote Code Execution - CVE:CVE-2026-63030

N/A

Block

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Managed Ruleset

...63167195

N/A

Generic Rules - RCE

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...72952826

N/A

Generic Rules - Information Disclosure

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...930091a3

N/A

Generic Rules - Auth Bypass - 2

N/A

Block

This is a new detection.

Cloudflare Managed Ruleset

...2049a60c

N/A

Generic Rules - Command Execution - Body - Beta

Disabled

-

This detection has been removed.

Cloudflare Managed Ruleset

...836855a4

N/A

Generic Rules - Command Execution - Header - Beta

Disabled

-

This detection has been removed.

Cloudflare Managed Ruleset

...6d060a0d

N/A

Generic Rules - Command Execution - URI - Beta

Disabled

-

This detection has been removed.

Fetched July 21, 2026

Adobe ColdFusion and WordPress CVEs blocked; SSRF, LFI… — releases.sh