Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-48277: ColdFusion: Unvalidated Input Can Execute Malicious Code
CVE-2026-48277
Summary
Versions 2025.9 and earlier of ColdFusion are vulnerable to a security flaw that could allow hackers to run malicious code on your server. This could lead to unauthorized access or data theft. To protect your system, update to the latest version of ColdFusion as soon as possible.
Original title
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploita...
Original description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
10.0
Vulnerability type
CWE-20
Improper Input Validation
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 30 Jun 2026