Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-48322

Adobe ColdFusion code injection — CVSS 9.6

Code injection in Adobe ColdFusion allows unauthenticated remote code execution. Patched in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

cat cve-2026-48322.json
Vendor
Adobe
Product
ColdFusion 2023, ColdFusion 2025
CVSS
9.6
EPSS (exploit probability)
1.2%
Status
patched
Published

Adobe ColdFusion contains a code injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on affected installations. The flaw was addressed in Adobe’s July 2026 security update, which shipped fixes for eight ColdFusion criticals in the same batch.

Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. ColdFusion has a documented history of rapid exploitation following advisory publication — treat this as an emergency-priority patch if the server is internet-exposed.

Source: NVD · Adobe Security Bulletin