ColdFusion code bug can let attackers run commands

Published July 7, 2026 CVE-2026-48282

Adobe ColdFusion has a flaw that lets attackers bypass security and run commands on your server as if they were you. This can let them steal data or take over your site.

Severity
CriticalCVSS 3.1 · 10.0
Fix
Not confirmedLast checked on Aug 27, 2026
Affected versions
through 9; through 20
Weakness
CWE-22Path Traversal
Exploit likelihood
42% in 30 daysEPSS, higher than 99% of known flaws
Affects
ColdFusion 2025+1 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Jul 7, 2026
Federal fix deadline
Jul 10, 2026

How it works

An attacker sends a specially crafted request to ColdFusion that tricks it into reading files outside its allowed folder, then runs commands on your server.

What to do

Check whether the installed ColdFusion version is older than the fixed version in the vendor advisory or current release.

Update ColdFusion through its normal update channel, then confirm the installed version matches the newest vendor release.

Technical details

Affected software: ColdFusion 2025by Adobe, ColdFusion 2023by Adobe

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator

References