Junglewise Threat Intelligence

CVE-2026-47928: Adobe ColdFusion improper input validation code execution

CVE-2026-47928 · Severity: critical · CVSS 9.6 · Published 2026-06-09

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a critical security flaw. This vulnerability allows an attacker to execute unauthorized commands on the server without any user interaction. If exploited, this could lead to a complete takeover of the application server, potentially resulting in data theft or service disruption.

Technical details

Adobe ColdFusion is vulnerable to arbitrary code execution due to improper input validation (CWE-20). The flaw exists in versions 2023.19, 2025.8 and earlier. An attacker can exploit this vulnerability over the network (specifically via an adjacent vector according to the CVSS string) without requiring any authentication or user interaction. Successful exploitation allows for code execution in the context of the current user and results in a changed scope, indicating the attacker may gain access to resources beyond the ColdFusion environment itself. Adobe has addressed this in security bulletin APSB26-64.

Affected products

  • Adobe ColdFusion 2023.19, 2025.8 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats