Adobe ColdFusion Web application server since 1995. Tag or script based programming language CFML.
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Adobe ColdFusion.
Recent Adobe ColdFusion Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-90 | Security updates available for Adobe ColdFusion | APSB26-90 | August 11, 2026 |
| APSB26-82 | Security updates available for Adobe ColdFusion | APSB26-82 | July 14, 2026 |
| APSB26-68 | Security updates available for Adobe ColdFusion | APSB26-68 | June 30, 2026 |
| APSB26-64 | Security updates available for Adobe ColdFusion | APSB26-38 APSB26-64 | June 9, 2026 |
| APSB26-38 | Security updates available for Adobe ColdFusion | APSB26-38 | April 14, 2026 |
| APSB26-12 | Security updates available for Adobe ColdFusion | APSB26-12 | January 13, 2026 |
| APSB25-105 | Security updates available for Adobe ColdFusion | APSB25-105 | December 9, 2025 |
| APSB25-93 | Security updates available for Adobe ColdFusion | APSB25-93 | September 9, 2025 |
| APSB25-69 | Security updates available for Adobe ColdFusion | APSB25-69 | July 8, 2025 |
| APSB25-52 | Security updates available for Adobe ColdFusion | APSB25-52 | May 13, 2025 |
Known Exploited Adobe ColdFusion Vulnerabilities
The following Adobe ColdFusion vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Adobe ColdFusion Path Traversal Vulnerability |
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. CVE-2026-48282 Exploit Probability: 99.0% |
July 7, 2026 |
| Adobe ColdFusion Deserialization Vulnerability |
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. CVE-2017-3066 Exploit Probability: 90.6% |
February 24, 2025 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. CVE-2024-20767 Exploit Probability: 98.5% |
December 16, 2024 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CVE-2023-29300 Exploit Probability: 100.0% |
January 8, 2024 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. CVE-2023-38203 Exploit Probability: 96.5% |
January 8, 2024 |
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability |
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. CVE-2023-26359 Exploit Probability: 17.9% |
August 21, 2023 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. CVE-2023-29298 Exploit Probability: 99.8% |
July 20, 2023 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. CVE-2023-38205 Exploit Probability: 99.8% |
July 20, 2023 |
| Adobe ColdFusion Improper Access Control Vulnerability |
Adobe ColdFusion contains an improper access control vulnerability that allows for remote code execution. CVE-2023-26360 Exploit Probability: 97.3% |
March 15, 2023 |
| Adobe ColdFusion Directory Traversal Vulnerability |
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. CVE-2010-2861 Exploit Probability: 99.7% |
March 25, 2022 |
| Adobe ColdFusion Information Disclosure Vulnerability |
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. CVE-2013-0631 Exploit Probability: 65.9% |
March 7, 2022 |
| Adobe ColdFusion Directory Traversal Vulnerability |
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. CVE-2013-0629 Exploit Probability: 65.9% |
March 7, 2022 |
| Adobe ColdFusion Authentication Bypass Vulnerability |
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. CVE-2013-0625 Exploit Probability: 93.8% |
March 7, 2022 |
| Adobe ColdFusion Authentication Bypass Vulnerability |
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. CVE-2013-0632 Exploit Probability: 93.7% |
March 3, 2022 |
| Adobe ColdFusion Deserialization of Untrusted Data vulnerability |
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution. CVE-2018-4939 Exploit Probability: 62.9% |
November 3, 2021 |
| Adobe ColdFusion Remote Code Execution |
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution. CVE-2018-15961 Exploit Probability: 100.0% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 15 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
EOL Dates
Ensure that you are using a supported version of Adobe ColdFusion. Here are some end of life, and end of support dates for Adobe ColdFusion.
| Release | EOL Date | End of Extended Support | Status |
|---|---|---|---|
| 2025 | April 8, 2030 | April 8, 2031 |
Active
Adobe ColdFusion 2025 will become EOL in 4 years (in 2030). |
| 2023 | May 16, 2028 | May 16, 2029 |
Active
Adobe ColdFusion 2023 will become EOL in two years (in 2028). |
| 2021 | December 9, 2025 | November 10, 2026 |
EOL
Adobe ColdFusion 2021 became EOL in 2025 and the extended support period ends in 2026. |
| 2018 | July 19, 2023 | July 13, 2024 |
EOL
Adobe ColdFusion 2018 became EOL in 2023 and the extended support period ended in 2024. |
| 2016 | March 22, 2021 | February 17, 2022 |
EOL
Adobe ColdFusion 2016 became EOL in 2021 and the extended support period ended in 2022. |
| 11 | June 11, 2019 | April 30, 2021 |
EOL
Adobe ColdFusion 11 became EOL in 2019 and the extended support period ended in 2021. |
| 10 | May 16, 2017 | May 16, 2019 |
EOL
Adobe ColdFusion 10 became EOL in 2017 and the extended support period ended in 2019. |
Extended Support differs by vendor, and may cost additional fees. Check with Adobe to see how they define extended support.
By the Year
In 2026 there have been 56 vulnerabilities in Adobe ColdFusion with an average score of 8.1 out of ten. Last year, in 2025 ColdFusion had 51 security vulnerabilities published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.64.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 56 | 8.06 |
| 2025 | 51 | 7.42 |
| 2024 | 6 | 7.63 |
| 2023 | 18 | 7.80 |
| 2022 | 14 | 7.99 |
| 2021 | 4 | 5.45 |
| 2020 | 7 | 7.67 |
| 2019 | 10 | 7.95 |
| 2018 | 14 | 8.14 |
It may take a day or so for new ColdFusion vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe ColdFusion Security Vulnerabilities
ColdFusion Incorrect Auth Leading to Code Execution
CVE-2026-71387
8.8 - High
- August 11, 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.
AuthZ
ColdFusion OS Command Injection Security Feature Bypass
CVE-2026-48385
7.7 - High
- August 11, 2026
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Shell injection
Adobe Acrobat Reader Incorrect Authorization Bypass (CVE-2026-71383)
CVE-2026-71383
7.3 - High
- August 11, 2026
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
AuthZ
Adobe Reader Improper Input Validation Allows Sec Feature Bypass
CVE-2026-21279
8.2 - High
- August 11, 2026
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
Improper Input Validation
ColdFusion Improper Input Validation Leads to DoS (CVE-2026-48384)
CVE-2026-48384
4.9 - Medium
- August 11, 2026
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Improper Input Validation
ColdFusion Incorrect Auth Enables DoS Crash
CVE-2026-48375
6.5 - Medium
- August 11, 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
AuthZ
Adobe Acrobat Reader Improper Output Encoding Bypass to Unprivileged Write
CVE-2026-48376
5.4 - Medium
- August 11, 2026
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
Output Sanitization
Adobe Stored XSS in Form Fields
CVE-2026-21269
4.6 - Medium
- August 11, 2026
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
XSS
Adobe ColdFusion Heap Buffer Overflow Remote Code Execution
CVE-2026-48440
8.1 - High
- August 11, 2026
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Heap-based Buffer Overflow
Adobe Acrobat Reader CVE-2026-34635 Hardcoded Crypto Key Bypass
CVE-2026-34635
8.4 - High
- August 11, 2026
is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Use of Hard-coded Cryptographic Key
Broken Crypto in Adobe ColdFusion Exposes Sensitive Memory
CVE-2026-48386
7.5 - High
- August 11, 2026
ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
Use of a Broken or Risky Cryptographic Algorithm
ColdFusion OS Command Injection (CVE-2026-48362) Arbitrary Code Exec
CVE-2026-48362
10 - Critical
- August 11, 2026
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Shell injection
Adobe Reader XSS allows arbitrary code exec in admin zone
CVE-2026-71386
8.8 - High
- August 11, 2026
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
XSS
Adobe CVE-2026-71384: Incorrect Auth Bypass Unrestricted Access
CVE-2026-71384
9.6 - Critical
- August 11, 2026
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
Adobe Acrobat Reader Incorrect Auth Priv Esc CVE-2026-25652
CVE-2026-25652
7.8 - High
- August 11, 2026
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
AuthZ
Adobe Acrobat Improper Input Validation Priv Escalation via Mal File
CVE-2026-21273
8.7 - High
- August 11, 2026
is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Improper Input Validation
Adobe ColdFusion Reflected XSS via Malicious File (CVE-2026-48320)
CVE-2026-48320
8.5 - High
- July 14, 2026
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
XSS
ColdFusion SQL Injection Leading to Arbitrary Code Execution
CVE-2026-48324
9.1 - Critical
- July 14, 2026
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
SQL Injection
ColdFusion SSRF Bypass Enabling Unauthorized Read Access (CVE202648332)
CVE-2026-48332
7.7 - High
- July 14, 2026
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
SSRF
Adobe ColdFusion Path Traversal: Arbitrary File Read
CVE-2026-48318
9.9 - Critical
- July 14, 2026
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
ColdFusion Path Traversal Allows Arbitrary File Read
CVE-2026-48338
6.8 - Medium
- July 14, 2026
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
Adobe ColdFusion Incorrect Auth Enables Arbitrary Code Exec
CVE-2026-48327
9 - Critical
- July 14, 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
ColdFusion Insufficient Session Expiration Allows Security Feature Bypass
CVE-2026-48329
2.7 - Low
- July 14, 2026
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Insufficient Session Expiration
Adobe ColdFusion Auth Bypass: Priv Escalation & R/W Access
CVE-2026-48321
9.3 - Critical
- July 14, 2026
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
Adobe ColdFusion Path Traversal Arbitrary Code Exec Hotspot
CVE-2026-48319
9.1 - Critical
- July 14, 2026
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
ColdFusion Improper Control of Code Generation - RCE
CVE-2026-48322
9.9 - Critical
- July 14, 2026
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Code Injection
Adobe ColdFusion Improper Input Validation Enables A/CExecution
CVE-2026-48284
9.6 - Critical
- July 14, 2026
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
ColdFusion Auth Bypass Enables Arbitrary Code Exec (CVE-2026-48325)
CVE-2026-48325
9.3 - Critical
- July 14, 2026
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Missing Authentication for Critical Function
Improper Input Validation in CF Allows SFB & Unauthorized Read Access
CVE-2026-48328
7.7 - High
- July 14, 2026
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
Adobe ColdFusion CVE-2026-48363: Uncontrolled SearchPath <=2025.9/2023.20
CVE-2026-48363
8.2 - High
- July 13, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
DLL preloading
Adobe ColdFusion <2025.9 Uncontrolled Search Path (UCE)
CVE-2026-48364
8.2 - High
- July 13, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
DLL preloading
ColdFusion <2025.9 Improper Input Validation Arbitrary Code Exec
CVE-2026-48316
10 - Critical
- July 06, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
Adobe ColdFusion Improper Input Validation Cmd Exec (2025.9)
CVE-2026-48315
9.3 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Improper Input Validation
Adobe ColdFusion 2025.9/2023.20 Improper Input Validation -> Arbitrary Code Exec
CVE-2026-48281
10 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
CVE-2026-48277: Adobe ColdFusion < 2025.9 IIV - arbitrary code exec
CVE-2026-48277
10 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
ColdFusion SSRF: Bypass security feature before v2025.9
CVE-2026-48285
8.6 - High
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
SSRF
ColdFusion 2025.9/2023.20 Path Traversal (Read/Write)
CVE-2026-48313
9.3 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
Adobe ColdFusion CVE-2026-48314: Path Traversal pre-2025.9/2023.20
CVE-2026-48314
6.5 - Medium
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.
Directory traversal
Reflected XSS in Adobe ColdFusion 2025.9/2023.20 and earlier
CVE-2026-48307
8.8 - High
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.
XSS
ColdFusion 2025.9: Unrestricted File Upload, Arbitrary Code Exec
CVE-2026-48276
10 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Unrestricted File Upload
Path Traversal in Adobe ColdFusion <=2025.9 for Arbitrary Code Execution
CVE-2026-48282
10 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
Adobe ColdFusion Unrestricted File Upload -> Exec (v < 2025.9)
CVE-2026-48283
10 - Critical
- June 30, 2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Unrestricted File Upload
Adobe ColdFusion 2023.19/2025.8 Incorrect Auth Arbitrary Code Exec
CVE-2026-47929
8.4 - High
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
ColdFusion 2023.19/2025.8 Path Traversal (PT) Bypass - Adobe
CVE-2026-47932
8.8 - High
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Directory traversal
ColdFusion XXE in XML Parser (before 2025.8)
CVE-2026-47960
7.4 - High
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
XXE
Adobe ColdFusion Improper Input Validation (Exec) <2025.8, 2023.19, earlier
CVE-2026-47928
9.6 - Critical
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
ColdFusion Improper Input Validation 2023.19/2025.8 Arbitrary Code Execution
CVE-2026-47931
8.4 - High
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Improper Input Validation
CVE-2026-47930: ColdFusion <2026 Improper Input Validation Bypass
CVE-2026-47930
8.1 - High
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Improper Input Validation
ColdFusion <= 2025.8 Stored XSS in form fields
CVE-2026-47933
4.8 - Medium
- June 09, 2026
ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerable component is restricted to an administrative network zone by default. Scope is changed.
XSS
ColdFusion Path Traversal (security bypass) before 2023.18
CVE-2026-34619
7.7 - High
- April 14, 2026
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.
Directory traversal
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Adobe ColdFusion or by Adobe? Click the Watch button to subscribe.