Adobe ColdFusion and WordPress CVEs blocked; SSRF, LFI rules upgraded
This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Adobe ColdFusion and WordPress, alongside enhanced generic protections against enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS) obfuscation techniques. To strengthen overall detection capabilities across emerging threat vectors, new emergency detection rules have also been deployed for Generic Rules - Unauthenticated Remote Code Execution (RCE), Generic Rules - Authentication Bypass (Auth Bypass - 2) and Generic Rules - Information Disclosure.
Key Findings
-
CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.
-
CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.
-
CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.
-
CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...215e7d31
N/A
SSRF - Restricted Protocol
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...a935ee5d
N/A
SSRF - Obfuscated Host
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...1b0230ac
N/A
LFI - Path Traversal
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...61349c8b
N/A
Adobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...9cb61eac
N/A
Adobe ColdFusion - Path Traversal - CVE:CVE-2026-48282
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...4ac5e21f
N/A
XSS — JS Bracket Concat Obfuscation - Body
Log
Disabled
This is a new detection.
Cloudflare Managed Ruleset
...f31f5559
N/A
XSS — JS Bracket Concat Obfuscation - Headers
Log
Disabled
This is a new detection.
Cloudflare Managed Ruleset
...987984fd
N/A
XSS — JS Bracket Concat Obfuscation - URI
Log
Block
This is a new detection.
Cloudflare Managed Ruleset
...ed933fcc
N/A
Wordpress - SQL Injection - CVE:CVE-2026-60137
N/A
Block
This was labeled as Generic Rules - SQLi.
Cloudflare Managed Ruleset
...550664b6
N/A
Wordpress - Remote Code Execution - CVE:CVE-2026-63030
N/A
Block
This was labeled as Generic Rules - Unauthenticated RCE.
Cloudflare Free Ruleset
...33697a1a
N/A
Wordpress - SQL Injection - CVE:CVE-2026-60137
N/A
Block
This was labeled as Generic Rules - SQLi.
Cloudflare Free Ruleset
...b5ec246a
N/A
Wordpress - Remote Code Execution - CVE:CVE-2026-63030
N/A
Block
This was labeled as Generic Rules - Unauthenticated RCE.
Cloudflare Managed Ruleset
...63167195
N/A
Generic Rules - RCE
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...72952826
N/A
Generic Rules - Information Disclosure
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...930091a3
N/A
Generic Rules - Auth Bypass - 2
N/A
Block
This is a new detection.
Cloudflare Managed Ruleset
...2049a60c
N/A
Generic Rules - Command Execution - Body - Beta
Disabled
-
This detection has been removed.
Cloudflare Managed Ruleset
...836855a4
N/A
Generic Rules - Command Execution - Header - Beta
Disabled
-
This detection has been removed.
Cloudflare Managed Ruleset
...6d060a0d
N/A
Generic Rules - Command Execution - URI - Beta
Disabled
-
This detection has been removed.
Fetched July 21, 2026
