Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48319: ColdFusion allows malicious code execution
CVE-2026-48319
CVE-2026-48319
Summary
ColdFusion has a security flaw that could let hackers run unauthorized code on your server. This could happen without anyone needing to click on anything, making it a serious concern. You should update ColdFusion to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | coldfusion 2025 | <= 10 |
| adobe | coldfusion 2023 | <= 21 |
| adobe | coldfusion |
2023 2025 cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* |
Original title
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current...
Original description
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1
9.1
Vulnerability type
CWE-22
Path Traversal
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026