Executive brief
Adobe ColdFusion, a platform for developing and deploying web applications, contains a critical security flaw. An attacker can exploit this vulnerability to take complete control of the server and execute malicious commands without any user interaction. This could lead to a total compromise of the application, including the theft of sensitive data or a complete shutdown of services.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw allows a remote, unauthenticated attacker to execute arbitrary code on the target system via the network. The vulnerability is characterized by a CVSS 3.1 score of 10.0, indicating that no user interaction is required and the security scope is changed, potentially allowing an attacker to impact the underlying host or other integrated systems. Adobe has addressed this in security bulletin APSB26-68.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory: Adobe security bulletin APSB26-68 published