Adobe ColdFusion code injection — CVSS 9.6
Code injection in Adobe ColdFusion allows unauthenticated remote code execution. Patched in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
- Vendor
- Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- CVSS
- 9.6
- EPSS (exploit probability)
- 1.2%
- Status
- patched
- Published
Adobe ColdFusion contains a code injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on affected installations. The flaw was addressed in Adobe’s July 2026 security update, which shipped fixes for eight ColdFusion criticals in the same batch.
Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. ColdFusion has a documented history of rapid exploitation following advisory publication — treat this as an emergency-priority patch if the server is internet-exposed.
Source: NVD · Adobe Security Bulletin
