Executive brief
Adobe ColdFusion is a web application server used to build and deploy dynamic websites and applications. A code injection vulnerability allows attackers to execute arbitrary code on servers running the affected version without requiring user interaction, potentially compromising the entire application and underlying system.
Technical details
The vulnerability is an improper neutralization of directives in dynamically evaluated code (eval injection) in Adobe ColdFusion. The vulnerability allows an attacker to inject and execute arbitrary code through unsafe evaluation of user-supplied or attacker-controlled input. No user interaction is required for exploitation, and the attack is network-accessible. An attacker can achieve remote code execution in the context of the ColdFusion server process. Patches are expected to be available from Adobe.
Affected products
- Adobe ColdFusion
Timeline
- 2026-09-08: disclosed