Heap-based Buffer Overflow in ColdFusion by Adobe
CVE-2026-48440

8.1HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48440?

Adobe ColdFusion is susceptible to a Heap-based Buffer Overflow vulnerability that may allow an attacker to execute arbitrary code within the context of the current user. The exploitability of this issue is subject to specific conditions beyond the control of the attacker, making it a critical concern for users. Importantly, this vulnerability can be exploited without requiring any user interaction, thus potentially exposing sensitive environments to risk.

Affected Version(s)

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2023 0 <= 2023.0.22

ColdFusion 2025 0 <= 2025.0.11

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.