Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48322: ColdFusion Code Injection Vulnerability Allows Malicious Code Execution

CVE-2026-48322 CVE-2026-48322
Summary

ColdFusion software contains a vulnerability that allows an attacker to execute malicious code on a user's system. This means an attacker could potentially take control of a user's account and access sensitive information. To protect yourself, update your ColdFusion software as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
adobe coldfusion 2025 <= 10
adobe coldfusion 2023 <= 21
adobe coldfusion 2023
2025
cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*
Original title
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation o...
Original description
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd CVSS3.1 9.6
Vulnerability type
CWE-94 Code Injection
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026