top of page
perceptive_background_267k.jpg

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the …

Published:

29 juni 2026 om 22:00:00

Alert date:

30 juni 2026 om 20:03:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Zero-Day Vulnerabilities, Web Technologies, Enterprise Applications

Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability tracked as CVE-2026-48281. The vulnerability can result in arbitrary code execution in the context of the current user. Notably, exploitation does not require user interaction, making it particularly dangerous. The scope is marked as changed, indicating impact can extend beyond the vulnerable component. Adobe has issued a security advisory (APSB26-68) addressing this issue. The vulnerability is currently undergoing analysis by NVD. Given the no-user-interaction requirement and arbitrary code execution potential, this represents a critical risk to ColdFusion deployments. Organizations running affected versions should apply patches immediately upon availability.

Technical details

Mitigation steps:

Affected products:

Adobe ColdFusion 2025.9
Adobe ColdFusion 2023.20

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page