Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-48276: ColdFusion versions 2025.9 and earlier: Malicious file upload risk
CVE-2026-48276
Summary
ColdFusion versions 2025.9 and earlier are at risk of a security issue that allows hackers to upload malicious files, potentially allowing them to execute unauthorized code on the system. This issue can be exploited without user interaction, making it a concern for administrators. To protect your system, update to the latest version of ColdFusion.
Original title
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the ...
Original description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
10.0
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 30 Jun 2026