CVE-2026-48281
Critical · CVSS 10.0Adobe ColdFusion — Improper Input Validation leading to arbitrary code execution (RCE)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-20
Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionAPSB26-68CVE-2026-48281CWE-20input validationcode execution
Keywords CVE-2026-48281ColdFusion RCEAPSB26-68ColdFusion 2025 exploitColdFusion 2023 exploitColdFusion improper input validationColdFusion arbitrary code executionColdFusion PoCAdobe ColdFusion vulnerability 2026
Versions: ColdFusion 2025 <= 2025.9, ColdFusion 2023 <= 2023.20
References
Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z