Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-48282: ColdFusion: Path Traversal Vulnerability Can Execute Malicious Code
Known exploited
Exploitation likelihood: 29%
CVE-2026-48282
CVE-2026-48282
CVE-2026-48282
Summary
ColdFusion versions 2025.9 and earlier are at risk of allowing attackers to execute malicious code on a server without needing user interaction. This means that an attacker could potentially take control of the server, potentially leading to data breaches or other security issues. Update ColdFusion to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion |
<= 2023.20 2023 2025 |
Original title
Adobe ColdFusion Path Traversal Vulnerability
Original description
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
nvd CVSS3.1
10.0
Vulnerability type
CWE-22
Path Traversal
Published: 7 Jul 2026 · Updated: 9 Jul 2026 · First seen: 30 Jun 2026