Improper Input Validation Vulnerability in Adobe ColdFusion Products
CVE-2026-27304

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-27304?

Adobe ColdFusion versions 2023.18, 2025.6 and earlier are susceptible to an improper input validation flaw that may allow attackers to execute arbitrary code within the context of the current user. This vulnerability can be exploited without any user interaction, raising significant security concerns for users of affected ColdFusion versions. Organizations using these products should take immediate action to mitigate the risks associated with this security issue.

Affected Version(s)

ColdFusion 0 <= 2025.6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.