Junglewise Threat Intelligence

CVE-2026-48277: Adobe ColdFusion improper input validation arbitrary code execution

CVE-2026-48277 · Severity: critical · CVSS 10 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security flaw. This vulnerability allows an attacker to remotely take control of the server and execute unauthorized commands without any user interaction. This could lead to a complete compromise of the application, including the theft of sensitive data and total disruption of services.

Technical details

An Improper Input Validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user via the network. The vulnerability is characterized by a CVSS 3.1 score of 10.0, indicating a critical impact on confidentiality, integrity, and availability with a changed scope. No user interaction is required for successful exploitation. Users are advised to review Adobe security bulletin APSB26-68 for patching information.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: advisory: Adobe published security bulletin APSB26-68
  • 2026-06-30: disclosed: CVE-2026-48277 published to the NVD dataset

References

Related threats