Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security flaw. This vulnerability allows an attacker to inject and execute malicious code on the server without any interaction from a legitimate user. If exploited, this could lead to a complete takeover of the application server and unauthorized access to sensitive business data.
Technical details
Adobe ColdFusion is vulnerable to Improper Control of Generation of Code (CWE-94), commonly known as Code Injection. The vulnerability exists in ColdFusion 2023 (versions 21 and below) and ColdFusion 2025 (versions 10 and below). An attacker with low-privileged network access can exploit this flaw to execute arbitrary code in the context of the current user. The exploit does not require user interaction and results in a 'Scope Changed' (S:C) impact, indicating the attacker can impact components beyond the immediate security scope of the vulnerable application. Adobe has released updates (ColdFusion 2023 Update 22 and ColdFusion 2025 Update 11) to address this issue.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory