Improper Input Validation in ColdFusion by Adobe
CVE-2026-48281
10CRITICAL
What is CVE-2026-48281?
Adobe ColdFusion contains an improper input validation vulnerability in versions 2025.9, 2023.20, and earlier. This flaw enables arbitrary code execution in the context of the current user, and it can be exploited without requiring user interaction. Attackers can potentially leverage this issue to execute unauthorized commands, altering the intended functionality of the application. It is crucial for users to apply updates and patches released by Adobe to protect against potential exploitation.
Affected Version(s)
ColdFusion 0 <= 2023.20