Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security flaw. An attacker could exploit this vulnerability to run unauthorized commands and take control of the server. This could lead to the theft of sensitive data or a complete compromise of the application environment without any action from a legitimate user.
Technical details
Adobe ColdFusion is vulnerable to arbitrary code execution due to improper input validation (CWE-20). The flaw exists in versions 2023.18, 2025.6, and earlier. An unauthenticated attacker on the adjacent network can exploit this vulnerability without any user interaction. Successful exploitation allows for code execution in the context of the current user, potentially leading to full system compromise. Adobe has released security bulletin APSB26-38 to address this issue.
Affected products
- Adobe ColdFusion 2023.18, 2025.6 and earlier
Timeline
- 2026-04-14: advisory: Initial advisory published by Adobe
- 2026-04-14: disclosed