Technology · Adobe
Adobe ColdFusion vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 70 vulnerabilities in Adobe ColdFusion: 0 in the last 7 days and 37 in the last 90 days, 36 of them critical and 17 exploited in the wild. The most recent, CVE-2026-76190, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 37
- Critical, all time
- 36
- Exploited in the wild
- 17
About Adobe ColdFusion
A commercial web application development platform that uses the CFML scripting language.
Latest Adobe ColdFusion vulnerabilities
- CVE-2026-76190: Adobe ColdFusion code injection in dynamically evaluated codehighCVSS 8.6EPSS 0.8%
- CVE-2026-76000: Adobe ColdFusion uncontrolled resource consumption in parsermediumCVSS 6.5EPSS 0.4%
- CVE-2026-75999: Adobe ColdFusion improper input validation remote code executionhighCVSS 8.4EPSS 0.5%
- CVE-2026-75998: Adobe ColdFusion improper access control arbitrary file readhighCVSS 7.5EPSS 0.8%
- CVE-2026-75993: Adobe ColdFusion reflected cross-site scriptinghighCVSS 8.5EPSS 0.4%
- CVE-2026-75746: Adobe ColdFusion SQL injection with arbitrary code executioncriticalCVSS 9.1EPSS 1.0%
- CVE-2026-48273: Adobe ColdFusion eval injection in dynamically evaluated codecriticalCVSS 9.9EPSS 1.3%
- CVE-2026-83961: Adobe ColdFusion improper authentication privilege escalationhighCVSS 7.1EPSS 0.4%
- CVE-2026-21279: Adobe ColdFusion improper input validation security feature bypasshighCVSS 8.2EPSS 0.8%
- CVE-2026-21273: Adobe ColdFusion improper input validation privilege escalationhighCVSS 8.7EPSS 0.9%
- CVE-2026-21269: Adobe ColdFusion stored XSS in form fieldsmediumCVSS 4.6EPSS 0.5%
- CVE-2026-48338: Adobe ColdFusion path traversal arbitrary file readmediumCVSS 6.8
- CVE-2026-48332: Adobe ColdFusion SSRF in security feature bypasshighCVSS 7.7
- CVE-2026-48329: Adobe ColdFusion insufficient session expirationlowCVSS 2.7
- CVE-2026-48328: Adobe ColdFusion security feature bypass via improper input validationhighCVSS 7.7
- CVE-2026-48327: Adobe ColdFusion incorrect authorization in code executioncriticalCVSS 9
- CVE-2026-48325: Adobe ColdFusion missing authentication for critical functioncriticalCVSS 9.3
- CVE-2026-48324: Adobe ColdFusion SQL injection leading to arbitrary code executioncriticalCVSS 9.1
- CVE-2026-48322: Adobe ColdFusion code injection in ColdFusion 2023 and 2025criticalCVSS 9.6
- CVE-2026-48321: Adobe ColdFusion privilege escalation via incorrect authorizationcriticalCVSS 9.3
- CVE-2026-48320: Adobe ColdFusion reflected XSShighCVSS 8.5
- CVE-2026-48319: Adobe ColdFusion path traversal in directory handlingcriticalCVSS 9.1
- CVE-2026-48318: Adobe ColdFusion path traversal arbitrary file readcriticalCVSS 9.9
- CVE-2026-48284: Adobe ColdFusion arbitrary code execution via improper input validationcriticalCVSS 9.6
- CVE-2026-48364: Adobe ColdFusion uncontrolled search path element vulnerabilityhighCVSS 8.2
Most severe Adobe ColdFusion vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-48282: Adobe ColdFusion path traversal in multiple versionscriticalexploited in the wildCVSS 10EPSS 1.0%
- CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-29300: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-38203: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-26360: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2010-2861: Adobe ColdFusion Directory Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2013-0625: Adobe ColdFusion Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2013-0632: Adobe ColdFusion Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2018-4939: Adobe ColdFusion Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 10 | 7 | |
| 6 Jul 2026 | 1 | 1 | |
| 13 Jul 2026 | 15 | 8 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 3 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 7 | 2 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/coldfusion.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Adobe ColdFusion vulnerabilities", https://junglewise.ai/threats/technologies/coldfusion, 26 September 2026.