Unrestricted File Upload Vulnerability in Adobe ColdFusion
CVE-2026-48276
10CRITICAL
What is CVE-2026-48276?
Adobe ColdFusion versions 2025.9 and 2023.20 are susceptible to a vulnerability that permits unrestricted file uploads of potentially dangerous file types. An attacker can exploit this flaw to execute arbitrary code within the context of the affected user. This vulnerability can be exploited without any user interaction, posing significant security risks to systems running these versions of ColdFusion.
Affected Version(s)
ColdFusion 0 <= 2023.20