CVE-2026-48284
Critical · CVSS 9.6Adobe ColdFusion — Improper Input Validation Remote Code Execution
- CVSS
- 9.6
- nvd
- EPSS
- 28.0%
- 98th pct
- KEV
- No
- Class
- other
- CWE-20
Description
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols ColdFusionAPSB26-82CVE-2026-48284arbitrary code executioninput validationCWE-20
Keywords CVE-2026-48284APSB26-82ColdFusion RCEColdFusion improper input validationColdFusion arbitrary code executionColdFusion exploit 2026Adobe ColdFusion PoC
Versions: versions affected per APSB26-82
References
Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z