CVE-2026-48324 – Adobe ColdFusion

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“When a web platform accumulates critical flaws across multiple attack paths, patching becomes a business priority—not a maintenance task.”

Adobe ColdFusion addresses thirteen vulnerabilities affecting ColdFusion 2025 and ColdFusion 2023.20 and earlier. The update resolves critical issues involving improper input validation, path traversal, code injection, SQL injection, missing authentication, and authorization weaknesses, along with high-severity vulnerabilities involving uncontrolled search paths, reflected cross-site scripting (XSS), and server-side request forgery (SSRF). Several of the critical vulnerabilities can be exploited without user interaction and could lead to arbitrary code execution, privilege escalation, unauthorized file access, or security feature bypass.

CVE-2026-48284 has a CVSS score of 9.6, Critical severity. CVE-2026-48318 has a CVSS score of 9.9, Critical severity. CVE-2026-48319 has a CVSS score of 9.1, Critical severity. CVE-2026-48321 has a CVSS score of 9.3, Critical severity. CVE-2026-48322 has a CVSS score of 9.6, Critical severity. CVE-2026-48324 has a CVSS score of 9.1, Critical severity. CVE-2026-48325 has a CVSS score of 9.3, Critical severity. CVE-2026-48327 has a CVSS score of 9.0, Critical severity. CVE-2026-48363 has a CVSS score of 8.2, High severity. CVE-2026-48364 has a CVSS score of 8.2, High severity. CVE-2026-48320 has a CVSS score of 8.5, High severity. CVE-2026-48328 has a CVSS score of 7.7, High severity. CVE-2026-48332 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Adobe Coldfusion
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-89
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.