Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. If exploited, an attacker could take full control of the server, potentially leading to the theft of sensitive data, service disruptions, or further attacks on the internal network. This vulnerability is particularly dangerous because it can be triggered remotely without any interaction from a legitimate user.
Technical details
This vulnerability (CWE-434) exists in Adobe ColdFusion due to insufficient validation of files uploaded to the server. An unauthenticated remote attacker can upload a malicious file (such as a web shell) and execute it in the context of the current user. The flaw is rated with a CVSS score of 10.0 because it requires no user interaction, no special privileges, and has a high impact on confidentiality, integrity, and availability, with a changed scope indicating potential impact beyond the ColdFusion application itself. Affected versions include 2025.9, 2023.20, and earlier; users should refer to Adobe security bulletin APSB26-68 for patching information.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory: Adobe security bulletin APSB26-68 published