Impact
The vulnerability found in Adobe ColdFusion arises from improper input validation, allowing an attacker to execute arbitrary code in the context of the current user. This flaw can be triggered without any user interaction, meaning that a remote attacker could leverage single‑click exploitation. The impact is severe, granting full control over the affected system where the ColdFusion service runs.
Affected Systems
Adobe ColdFusion is affected for versions 2023.18, 2025.6, and all earlier releases. All users running these versions on any platform are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity flaw capable of remote code execution. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of user interaction requirement and the broad applicability of the flaw make exploitation likely in environments where sufficient network exposure exists.
OpenCVE Enrichment