ColdFusion Adobe ColdFusion Web application server since 1995. Tag or script based programming language CFML.

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Adobe ColdFusion.

Recent Adobe ColdFusion Security Advisories

Advisory Title Published
APSB26-90 Security updates available for Adobe ColdFusion | APSB26-90 August 11, 2026
APSB26-82 Security updates available for Adobe ColdFusion | APSB26-82 July 14, 2026
APSB26-68 Security updates available for Adobe ColdFusion | APSB26-68 June 30, 2026
APSB26-64 Security updates available for Adobe ColdFusion | APSB26-38 APSB26-64 June 9, 2026
APSB26-38 Security updates available for Adobe ColdFusion | APSB26-38 April 14, 2026
APSB26-12 Security updates available for Adobe ColdFusion | APSB26-12 January 13, 2026
APSB25-105 Security updates available for Adobe ColdFusion | APSB25-105 December 9, 2025
APSB25-93 Security updates available for Adobe ColdFusion | APSB25-93 September 9, 2025
APSB25-69 Security updates available for Adobe ColdFusion | APSB25-69 July 8, 2025
APSB25-52 Security updates available for Adobe ColdFusion | APSB25-52 May 13, 2025

Known Exploited Adobe ColdFusion Vulnerabilities

The following Adobe ColdFusion vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Adobe ColdFusion Path Traversal Vulnerability Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
CVE-2026-48282 Exploit Probability: 99.0%
July 7, 2026
Adobe ColdFusion Deserialization Vulnerability Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2017-3066 Exploit Probability: 90.6%
February 24, 2025
Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-20767 Exploit Probability: 98.5%
December 16, 2024
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-29300 Exploit Probability: 100.0%
January 8, 2024
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-38203 Exploit Probability: 96.5%
January 8, 2024
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
CVE-2023-26359 Exploit Probability: 17.9%
August 21, 2023
Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
CVE-2023-29298 Exploit Probability: 99.8%
July 20, 2023
Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
CVE-2023-38205 Exploit Probability: 99.8%
July 20, 2023
Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that allows for remote code execution.
CVE-2023-26360 Exploit Probability: 97.3%
March 15, 2023
Adobe ColdFusion Directory Traversal Vulnerability A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2010-2861 Exploit Probability: 99.7%
March 25, 2022
Adobe ColdFusion Information Disclosure Vulnerability Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
CVE-2013-0631 Exploit Probability: 65.9%
March 7, 2022
Adobe ColdFusion Directory Traversal Vulnerability Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
CVE-2013-0629 Exploit Probability: 65.9%
March 7, 2022
Adobe ColdFusion Authentication Bypass Vulnerability Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
CVE-2013-0625 Exploit Probability: 93.8%
March 7, 2022
Adobe ColdFusion Authentication Bypass Vulnerability An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
CVE-2013-0632 Exploit Probability: 93.7%
March 3, 2022
Adobe ColdFusion Deserialization of Untrusted Data vulnerability Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2018-4939 Exploit Probability: 62.9%
November 3, 2021
Adobe ColdFusion Remote Code Execution Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2018-15961 Exploit Probability: 100.0%
November 3, 2021

Of the known exploited vulnerabilities above, 15 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

EOL Dates

Ensure that you are using a supported version of Adobe ColdFusion. Here are some end of life, and end of support dates for Adobe ColdFusion.

Release EOL Date End of Extended Support Status
2025 April 8, 2030 April 8, 2031
Active

Adobe ColdFusion 2025 will become EOL in 4 years (in 2030).

2023 May 16, 2028 May 16, 2029
Active

Adobe ColdFusion 2023 will become EOL in two years (in 2028).

2021 December 9, 2025 November 10, 2026
EOL

Adobe ColdFusion 2021 became EOL in 2025 and the extended support period ends in 2026.

2018 July 19, 2023 July 13, 2024
EOL

Adobe ColdFusion 2018 became EOL in 2023 and the extended support period ended in 2024.

2016 March 22, 2021 February 17, 2022
EOL

Adobe ColdFusion 2016 became EOL in 2021 and the extended support period ended in 2022.

11 June 11, 2019 April 30, 2021
EOL

Adobe ColdFusion 11 became EOL in 2019 and the extended support period ended in 2021.

10 May 16, 2017 May 16, 2019
EOL

Adobe ColdFusion 10 became EOL in 2017 and the extended support period ended in 2019.

Extended Support differs by vendor, and may cost additional fees. Check with Adobe to see how they define extended support.

By the Year

In 2026 there have been 56 vulnerabilities in Adobe ColdFusion with an average score of 8.1 out of ten. Last year, in 2025 ColdFusion had 51 security vulnerabilities published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.64.




Year Vulnerabilities Average Score
2026 56 8.06
2025 51 7.42
2024 6 7.63
2023 18 7.80
2022 14 7.99
2021 4 5.45
2020 7 7.67
2019 10 7.95
2018 14 8.14

It may take a day or so for new ColdFusion vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Adobe ColdFusion Security Vulnerabilities

ColdFusion Incorrect Auth Leading to Code Execution
CVE-2026-71387 8.8 - High - August 11, 2026

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.

AuthZ

ColdFusion OS Command Injection Security Feature Bypass
CVE-2026-48385 7.7 - High - August 11, 2026

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

Shell injection

Adobe Acrobat Reader Incorrect Authorization Bypass (CVE-2026-71383)
CVE-2026-71383 7.3 - High - August 11, 2026

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

AuthZ

Adobe Reader Improper Input Validation Allows Sec Feature Bypass
CVE-2026-21279 8.2 - High - August 11, 2026

is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.

Improper Input Validation

ColdFusion Improper Input Validation Leads to DoS (CVE-2026-48384)
CVE-2026-48384 4.9 - Medium - August 11, 2026

ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Improper Input Validation

ColdFusion Incorrect Auth Enables DoS Crash
CVE-2026-48375 6.5 - Medium - August 11, 2026

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

AuthZ

Adobe Acrobat Reader Improper Output Encoding Bypass to Unprivileged Write
CVE-2026-48376 5.4 - Medium - August 11, 2026

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

Output Sanitization

Adobe Stored XSS in Form Fields
CVE-2026-21269 4.6 - Medium - August 11, 2026

is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

XSS

Adobe ColdFusion Heap Buffer Overflow Remote Code Execution
CVE-2026-48440 8.1 - High - August 11, 2026

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

Heap-based Buffer Overflow

Adobe Acrobat Reader CVE-2026-34635 Hardcoded Crypto Key Bypass
CVE-2026-34635 8.4 - High - August 11, 2026

is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.

Use of Hard-coded Cryptographic Key

Broken Crypto in Adobe ColdFusion Exposes Sensitive Memory
CVE-2026-48386 7.5 - High - August 11, 2026

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.

Use of a Broken or Risky Cryptographic Algorithm

ColdFusion OS Command Injection (CVE-2026-48362) Arbitrary Code Exec
CVE-2026-48362 10 - Critical - August 11, 2026

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Shell injection

Adobe Reader XSS allows arbitrary code exec in admin zone
CVE-2026-71386 8.8 - High - August 11, 2026

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

XSS

Adobe CVE-2026-71384: Incorrect Auth Bypass Unrestricted Access
CVE-2026-71384 9.6 - Critical - August 11, 2026

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

AuthZ

Adobe Acrobat Reader Incorrect Auth Priv Esc CVE-2026-25652
CVE-2026-25652 7.8 - High - August 11, 2026

is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

AuthZ

Adobe Acrobat Improper Input Validation Priv Escalation via Mal File
CVE-2026-21273 8.7 - High - August 11, 2026

is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Improper Input Validation

Adobe ColdFusion Reflected XSS via Malicious File (CVE-2026-48320)
CVE-2026-48320 8.5 - High - July 14, 2026

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

XSS

ColdFusion SQL Injection Leading to Arbitrary Code Execution
CVE-2026-48324 9.1 - Critical - July 14, 2026

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

SQL Injection

ColdFusion SSRF Bypass Enabling Unauthorized Read Access (CVE202648332)
CVE-2026-48332 7.7 - High - July 14, 2026

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

SSRF

Adobe ColdFusion Path Traversal: Arbitrary File Read
CVE-2026-48318 9.9 - Critical - July 14, 2026

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

Directory traversal

ColdFusion Path Traversal Allows Arbitrary File Read
CVE-2026-48338 6.8 - Medium - July 14, 2026

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

Directory traversal

Adobe ColdFusion Incorrect Auth Enables Arbitrary Code Exec
CVE-2026-48327 9 - Critical - July 14, 2026

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

AuthZ

ColdFusion Insufficient Session Expiration Allows Security Feature Bypass
CVE-2026-48329 2.7 - Low - July 14, 2026

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

Insufficient Session Expiration

Adobe ColdFusion Auth Bypass: Priv Escalation & R/W Access
CVE-2026-48321 9.3 - Critical - July 14, 2026

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

AuthZ

Adobe ColdFusion Path Traversal Arbitrary Code Exec Hotspot
CVE-2026-48319 9.1 - Critical - July 14, 2026

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Directory traversal

ColdFusion Improper Control of Code Generation - RCE
CVE-2026-48322 9.9 - Critical - July 14, 2026

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Code Injection

Adobe ColdFusion Improper Input Validation Enables A/CExecution
CVE-2026-48284 9.6 - Critical - July 14, 2026

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

ColdFusion Auth Bypass Enables Arbitrary Code Exec (CVE-2026-48325)
CVE-2026-48325 9.3 - Critical - July 14, 2026

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Missing Authentication for Critical Function

Improper Input Validation in CF Allows SFB & Unauthorized Read Access
CVE-2026-48328 7.7 - High - July 14, 2026

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

Adobe ColdFusion CVE-2026-48363: Uncontrolled SearchPath <=2025.9/2023.20
CVE-2026-48363 8.2 - High - July 13, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

DLL preloading

Adobe ColdFusion <2025.9 Uncontrolled Search Path (UCE)
CVE-2026-48364 8.2 - High - July 13, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

DLL preloading

ColdFusion <2025.9 Improper Input Validation Arbitrary Code Exec
CVE-2026-48316 10 - Critical - July 06, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

Adobe ColdFusion Improper Input Validation Cmd Exec (2025.9)
CVE-2026-48315 9.3 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Improper Input Validation

Adobe ColdFusion 2025.9/2023.20 Improper Input Validation -> Arbitrary Code Exec
CVE-2026-48281 10 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

CVE-2026-48277: Adobe ColdFusion < 2025.9 IIV - arbitrary code exec
CVE-2026-48277 10 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

ColdFusion SSRF: Bypass security feature before v2025.9
CVE-2026-48285 8.6 - High - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

SSRF

ColdFusion 2025.9/2023.20 Path Traversal (Read/Write)
CVE-2026-48313 9.3 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

Directory traversal

Adobe ColdFusion CVE-2026-48314: Path Traversal pre-2025.9/2023.20
CVE-2026-48314 6.5 - Medium - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.

Directory traversal

Reflected XSS in Adobe ColdFusion 2025.9/2023.20 and earlier
CVE-2026-48307 8.8 - High - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.

XSS

ColdFusion 2025.9: Unrestricted File Upload, Arbitrary Code Exec
CVE-2026-48276 10 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Unrestricted File Upload

Path Traversal in Adobe ColdFusion <=2025.9 for Arbitrary Code Execution
CVE-2026-48282 10 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Directory traversal

Adobe ColdFusion Unrestricted File Upload -> Exec (v < 2025.9)
CVE-2026-48283 10 - Critical - June 30, 2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Unrestricted File Upload

Adobe ColdFusion 2023.19/2025.8 Incorrect Auth Arbitrary Code Exec
CVE-2026-47929 8.4 - High - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

AuthZ

ColdFusion 2023.19/2025.8 Path Traversal (PT) Bypass - Adobe
CVE-2026-47932 8.8 - High - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Directory traversal

ColdFusion XXE in XML Parser (before 2025.8)
CVE-2026-47960 7.4 - High - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

XXE

Adobe ColdFusion Improper Input Validation (Exec) <2025.8, 2023.19, earlier
CVE-2026-47928 9.6 - Critical - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

ColdFusion Improper Input Validation 2023.19/2025.8 Arbitrary Code Execution
CVE-2026-47931 8.4 - High - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

Improper Input Validation

CVE-2026-47930: ColdFusion <2026 Improper Input Validation Bypass
CVE-2026-47930 8.1 - High - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

Improper Input Validation

ColdFusion <= 2025.8 Stored XSS in form fields
CVE-2026-47933 4.8 - Medium - June 09, 2026

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerable component is restricted to an administrative network zone by default. Scope is changed.

XSS

ColdFusion Path Traversal (security bypass) before 2023.18
CVE-2026-34619 7.7 - High - April 14, 2026

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.

Directory traversal

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Adobe ColdFusion or by Adobe? Click the Watch button to subscribe.

Adobe
Vendor

Adobe ColdFusion
Web application server since 1995. Tag or script based programming language CFML.

subscribe