CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-47928

Critical · CVSS 9.6

Adobe ColdFusion — Improper Input Validation leading to Arbitrary Code Execution (RCE)

CVSS
9.6
nvd
EPSS
2.48%
82th pct
KEV
No
Class
other
CWE-20, NVD-CWE-noinfo

Description

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Search profile — drives PoC discovery

Symbols ColdFusionAPSB26-64CVE-2026-47928CWE-20arbitrary code executionimproper input validation
Keywords CVE-2026-47928APSB26-64ColdFusion RCEColdFusion 2023 exploitColdFusion 2025 exploitColdFusion input validation bypassColdFusion arbitrary code executionColdFusion PoCAdobe ColdFusion vulnerability 2026
Versions: ColdFusion 2023 <= 2023.19, ColdFusion 2025 <= 2025.8

References

Status: enriched · ingested 2026-06-15T18:00:58.000Z · profiled 2026-06-16T18:20:23.035Z