CVE-2026-48284 – Adobe ColdFusion 2025

CVSS 9.6 CRITICAL Zero Day – Immediate Deployment

“When critical vulnerabilities require no user interaction, every unpatched server becomes an immediate business risk.”

Adobe has released security updates for ColdFusion 2025 to address eight critical vulnerabilities. These include path traversal, code injection, improper input validation, incorrect authorization, missing authentication, and SQL injection issues that could allow attackers to read sensitive files, execute arbitrary code, or gain unauthorized access without requiring user interaction.

CVE-2026-48318 has a CVSS score of 9.9, which is Critical severity. CVE-2026-48322 and CVE-2026-48284 each have a CVSS score of 9.6, which is Critical severity. CVE-2026-48321 and CVE-2026-48325 each have a CVSS score of 9.3, which is Critical severity. CVE-2026-48319 and CVE-2026-48324 each have a CVSS score of 9.1, which is Critical severity. CVE-2026-48327 has a CVSS score of 9.0, which is Critical severity. There are no verified reports of active exploitation or public proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Adobe Coldfusion
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.