CVE Record
[ CRITICAL ]CVE-2026-48284
Adobe ColdFusion input-validation failure — CVSS 9.6
Input-validation failure in Adobe ColdFusion enables unauthenticated remote code execution. Patched in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
- Vendor
- Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- CVSS
- 9.6
- EPSS (exploit probability)
- 4.9%
- Status
- patched
- Published
An input-validation failure in Adobe ColdFusion allows a remote unauthenticated attacker to execute arbitrary code. Part of Adobe’s July 2026 batch that included eight ColdFusion critical CVEs; patched simultaneously in the same update release.
Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. Internet-exposed ColdFusion instances should be treated as a priority-zero patch target — the platform has appeared repeatedly in CISA’s KEV catalog following advisory releases.
Source: NVD · Adobe Security Bulletin
