Junglewise Threat Intelligence

CVE-2026-48281: Adobe ColdFusion arbitrary code execution via improper input validation

CVE-2026-48281 · Severity: critical · CVSS 10 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for developing and deploying web applications, contains a critical security flaw. An attacker can exploit this vulnerability to take complete control of the server and execute malicious commands without any user interaction. This could lead to a total compromise of the application, including the theft of sensitive data or a complete shutdown of services.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to execute arbitrary code on the target system via the network. The vulnerability is characterized by a CVSS 3.1 score of 10.0, indicating that no user interaction is required and the security scope is changed, potentially allowing an attacker to impact the underlying host or other integrated systems. Adobe has addressed this in security bulletin APSB26-68.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory: Adobe security bulletin APSB26-68 published

References

Related threats