CVE-2026-47928
Critical · CVSS 9.6Adobe ColdFusion — Improper Input Validation leading to Arbitrary Code Execution (RCE)
- CVSS
- 9.6
- nvd
- EPSS
- 2.48%
- 82th pct
- KEV
- No
- Class
- other
- CWE-20, NVD-CWE-noinfo
Description
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionAPSB26-64CVE-2026-47928CWE-20arbitrary code executionimproper input validation
Keywords CVE-2026-47928APSB26-64ColdFusion RCEColdFusion 2023 exploitColdFusion 2025 exploitColdFusion input validation bypassColdFusion arbitrary code executionColdFusion PoCAdobe ColdFusion vulnerability 2026
Versions: ColdFusion 2023 <= 2023.19, ColdFusion 2025 <= 2025.8
References
Status: enriched · ingested 2026-06-15T18:00:58.000Z · profiled 2026-06-16T18:20:23.035Z