Executive brief
Adobe ColdFusion is an enterprise application development platform used to build and deploy web applications. An improper input validation vulnerability allows a low-privileged attacker to execute arbitrary code with the privileges of the current user. While the vulnerable component is restricted to administrative networks by default, exploitation requires a victim to open a malicious file, creating a foothold for code execution and potential compromise of the application server.
Technical details
ColdFusion contains an improper input validation vulnerability in an administrative-restricted component that permits arbitrary code execution. The vulnerability is triggered when a victim opens a malicious file, bypassing input validation controls and allowing an authenticated attacker with low privileges to inject and execute arbitrary code in the context of the application. The scope changes as a result of successful exploitation. No active exploitation in the wild has been reported as of the advisory date. Patches are expected to be available from Adobe via security bulletin APSB26-119.
Affected products
- Adobe ColdFusion
Timeline
- 2026-09-08: disclosed