Junglewise Threat Intelligence

CVE-2026-27306: Adobe ColdFusion improper input validation code execution

CVE-2026-27306 · Severity: high · CVSS 8.4 · Published 2026-04-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building web applications, is affected by a security flaw that could allow an attacker to run unauthorized commands on the server. To exploit this, an attacker needs high-level access and must trick a user into opening a malicious file. If successful, this could lead to a full system takeover or theft of sensitive application data.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. The flaw allows for arbitrary code execution in the context of the current user. While the CVSS vector indicates an adjacent network attack vector and high privileges are required, the advisory also notes that exploitation requires user interaction, specifically a victim opening a malicious file. Successful exploitation could lead to a complete compromise of the application server. Adobe has released security updates to address this issue in APSB26-38.

Affected products

  • Adobe ColdFusion 2023.18, 2025.6 and earlier

Timeline

  • 2026-04-14: advisory: Initial advisory published by Adobe and NVD
  • 2026-04-14: disclosed

References

Related threats