Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a critical security flaw. This vulnerability allows an attacker to execute unauthorized commands on the server without any interaction from a legitimate user. If exploited, this could lead to a complete takeover of the application server, resulting in the theft of sensitive data or a total disruption of business operations.
Technical details
Adobe ColdFusion (versions 2023 and 2025) contains an improper input validation vulnerability (CWE-20) that facilitates arbitrary code execution. The flaw exists in how the application processes input, allowing an attacker to run commands with the privileges of the ColdFusion service user. The attack vector is classified as 'Adjacent,' meaning the attacker must be on the same local network or subnet as the target. No authentication or user interaction is required for successful exploitation. The vulnerability is particularly severe because the CVSS metric indicates a 'Scope Change' (S:C), suggesting the impact can extend beyond the ColdFusion environment to the underlying host or other integrated systems. Adobe has released security updates (APSB26-82) to address these issues.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Adobe security bulletin APSB26-82 published.