Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-48283: ColdFusion versions 2025.9 and earlier allow attackers to run code as you.
CVE-2026-48283
Summary
Certain versions of ColdFusion, a web development platform, have a security flaw that lets attackers upload malicious files and run code under your account. This could be exploited without your knowledge or interaction, so it's essential to update your ColdFusion to the latest version to fix this issue.
Original title
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the ...
Original description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
10.0
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 30 Jun 2026