CVE-2026-48324 – Adobe ColdFusion
“When a web platform accumulates critical flaws across multiple attack paths, patching becomes a business priority—not a maintenance task.”
Adobe ColdFusion addresses thirteen vulnerabilities affecting ColdFusion 2025 and ColdFusion 2023.20 and earlier. The update resolves critical issues involving improper input validation, path traversal, code injection, SQL injection, missing authentication, and authorization weaknesses, along with high-severity vulnerabilities involving uncontrolled search paths, reflected cross-site scripting (XSS), and server-side request forgery (SSRF). Several of the critical vulnerabilities can be exploited without user interaction and could lead to arbitrary code execution, privilege escalation, unauthorized file access, or security feature bypass.
CVE-2026-48284 has a CVSS score of 9.6, Critical severity. CVE-2026-48318 has a CVSS score of 9.9, Critical severity. CVE-2026-48319 has a CVSS score of 9.1, Critical severity. CVE-2026-48321 has a CVSS score of 9.3, Critical severity. CVE-2026-48322 has a CVSS score of 9.6, Critical severity. CVE-2026-48324 has a CVSS score of 9.1, Critical severity. CVE-2026-48325 has a CVSS score of 9.3, Critical severity. CVE-2026-48327 has a CVSS score of 9.0, Critical severity. CVE-2026-48363 has a CVSS score of 8.2, High severity. CVE-2026-48364 has a CVSS score of 8.2, High severity. CVE-2026-48320 has a CVSS score of 8.5, High severity. CVE-2026-48328 has a CVSS score of 7.7, High severity. CVE-2026-48332 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.
Key Details
- Affected Product
- Adobe Coldfusion
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-89