Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a critical security flaw. An attacker could remotely execute malicious code on the server without any user interaction. This could lead to a complete takeover of the application and unauthorized access to sensitive data.
Technical details
Adobe ColdFusion is vulnerable to arbitrary code execution due to improper input validation (CWE-20). The vulnerability allows a remote, unauthenticated attacker to execute code in the context of the current user via the network. The exploit requires no user interaction and involves a scope change, indicating the impact may extend beyond the ColdFusion environment itself. Adobe has addressed this in security bulletin APSB26-68, and users are advised to update to the latest patched versions.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-07-06: advisory: Adobe published security bulletin APSB26-68 and NVD published CVE-2026-48316.