Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-48282: ColdFusion: Path Traversal Vulnerability Can Execute Malicious Code

Known exploited Exploitation likelihood: 29%
CVE-2026-48282 CVE-2026-48282 CVE-2026-48282
Summary

ColdFusion versions 2025.9 and earlier are at risk of allowing attackers to execute malicious code on a server without needing user interaction. This means that an attacker could potentially take control of the server, potentially leading to data breaches or other security issues. Update ColdFusion to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
adobe coldfusion <= 2023.20
2023
2025
Original title
Adobe ColdFusion Path Traversal Vulnerability
Original description
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
nvd CVSS3.1 10.0
Vulnerability type
CWE-22 Path Traversal
Published: 7 Jul 2026 · Updated: 9 Jul 2026 · First seen: 30 Jun 2026