Impact
ColdFusion is affected by an improper input validation flaw that can lead to arbitrary code execution in the context of the current user. The vulnerability is classified as CWE-20 and the change in scope indicates that a successful exploit could elevate the attacker’s privileges beyond the original application boundary, allowing full control over the host system.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are listed as affected. The advisory does not enumerate specific sub‑versions or release candidates, so administrators should verify whether their deployed release is covered by the published fix.
Risk and Exploitability
The CVSS score of 9.6 places this vulnerability in the critical range, and the EPSS score of 28% indicates a high likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. While the exact attack vector is not specified in the description, it is inferred that a remote actor can trigger the flaw by sending malicious input to a vulnerable ColdFusion endpoint, especially since exploitation does not require user interaction. The combination of a drastic scope change and a high exploitation probability makes this vulnerability a top priority for remediation.
OpenCVE Enrichment