Description
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.6 Critical
EPSS: 28.0% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ColdFusion is affected by an improper input validation flaw that can lead to arbitrary code execution in the context of the current user. The vulnerability is classified as CWE-20 and the change in scope indicates that a successful exploit could elevate the attacker’s privileges beyond the original application boundary, allowing full control over the host system.

Affected Systems

Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are listed as affected. The advisory does not enumerate specific sub‑versions or release candidates, so administrators should verify whether their deployed release is covered by the published fix.

Risk and Exploitability

The CVSS score of 9.6 places this vulnerability in the critical range, and the EPSS score of 28% indicates a high likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. While the exact attack vector is not specified in the description, it is inferred that a remote actor can trigger the flaw by sending malicious input to a vulnerable ColdFusion endpoint, especially since exploitation does not require user interaction. The combination of a drastic scope change and a high exploitation probability makes this vulnerability a top priority for remediation.

Generated by OpenCVE AI on August 3, 2026 at 03:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe ColdFusion security update that addresses the improper input validation flaw as soon as it becomes available.
  • Restrict network exposure to ColdFusion services by implementing firewall rules or VPN isolation to limit access to trusted IP ranges.
  • Deploy a web application firewall or enforce strict input filtering on deployed CFML code to block malicious payloads until the patch is installed.

Generated by OpenCVE AI on August 3, 2026 at 03:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025
Vendors & Products Adobe
Adobe coldfusion 2023
Adobe coldfusion 2025

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Title ColdFusion | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Coldfusion 2023 Coldfusion 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:34:09.877Z

Reserved: 2026-05-21T15:28:38.134Z

Link: CVE-2026-48284

cve-icon Vulnrichment

Updated: 2026-07-15T10:34:05.340Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation