Executive brief
Adobe ColdFusion, a platform for developing and deploying web applications, is affected by a security flaw that allows for unauthorized code execution. An attacker could use this vulnerability to take control of the server and access sensitive data or disrupt business operations. This issue can be exploited without any interaction from a legitimate user, though it requires the attacker to have high-level privileges on an adjacent network.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2023.19, 2025.8, and earlier. The flaw allows an attacker to execute arbitrary code in the context of the current user. The attack vector is restricted to the adjacent network (AV:A) and requires high privileges (PR:H) to execute. No user interaction is required for successful exploitation. The vulnerability results in a changed scope (S:C), impacting the confidentiality, integrity, and availability of the system. Adobe has addressed this in security bulletin APSB26-64.
Affected products
- Adobe ColdFusion 2023.19 and earlier, 2025.8 and earlier
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-64
- 2026-06-09: disclosed: CVE-2026-47931 published to the NVD