Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48284: ColdFusion User Input Validation Error Allows Code Execution
CVE-2026-48284
CVE-2026-48284
Summary
ColdFusion users are at risk of having malicious code executed on their accounts if an attacker sends them a malicious input. This can happen without the user's knowledge or action. To protect yourself, ensure you are running the latest version of ColdFusion and consider implementing additional security measures.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion 2025 | <= 10 |
| adobe | coldfusion 2023 | <= 21 |
| adobe | coldfusion |
2023 2025 cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* |
Original title
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require us...
Original description
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
9.6
Vulnerability type
CWE-20
Improper Input Validation
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026