Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security flaw. This vulnerability allows an attacker to remotely take control of the server and execute unauthorized commands without any user interaction. This could lead to a complete compromise of the application, including the theft of sensitive data and total disruption of services.
Technical details
An Improper Input Validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to execute arbitrary code in the context of the current user via the network. The vulnerability is characterized by a CVSS 3.1 score of 10.0, indicating a critical impact on confidentiality, integrity, and availability with a changed scope. No user interaction is required for successful exploitation. Users are advised to review Adobe security bulletin APSB26-68 for patching information.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: advisory: Adobe published security bulletin APSB26-68
- 2026-06-30: disclosed: CVE-2026-48277 published to the NVD dataset