ColdFusion code bug can let attackers run commands
Adobe ColdFusion has a flaw that lets attackers bypass security and run commands on your server as if they were you. This can let them steal data or take over your site.
- Severity
- CriticalCVSS 3.1 · 10.0
- Fix
- Not confirmedLast checked on Aug 27, 2026
- Affected versions
- through 9; through 20
- Weakness
- CWE-22Path Traversal
- Exploit likelihood
- 42% in 30 daysEPSS, higher than 99% of known flaws
- Affects
- ColdFusion 2025+1 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 7, 2026
- Federal fix deadline
- Jul 10, 2026
How it works
An attacker sends a specially crafted request to ColdFusion that tricks it into reading files outside its allowed folder, then runs commands on your server.
What to do
Check whether the installed ColdFusion version is older than the fixed version in the vendor advisory or current release.
Update ColdFusion through its normal update channel, then confirm the installed version matches the newest vendor release.
Technical details
Affected software: ColdFusion 2025by Adobe, ColdFusion 2023by Adobe
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- helpx.adobe.com · apsb26-68.html Vendor Advisory vendor advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource