CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability. Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent. Adobe ColdFusion Flaws […] The post Critical Adobe ColdFusion Vulnerabilities Allow Attackers to E

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code By Guru Baran August 12, 2026 Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability. Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent. Adobe ColdFusion Flaws Enable Code Execution The most alarming flaw resolved in this batch is CVE-2026-48362, an unauthenticated OS command injection vulnerability with a maximum CVSS base score of 10.0. The flaw allows remote, unauthenticated attackers to execute arbitrary operating system commands on vulnerable ColdFusion servers without any user interaction. On internet-exposed servers, this grants attackers an immediate path to full host takeover. In addition to command injection, Adobe resolved CVE-2026-48273, an eval injection flaw rated 9.9 on the CVSS scale. Although exploiting this bug requires low-level privileges, an authenticated user could still leverage it to run arbitrary code. Another critical fix addresses CVE-2026-48440 (CVSS 8.1), a heap-based buffer overflow that opens additional execution vectors. Addressing these critical Adobe vulnerabilities is essential for preventing host compromise across public web services. The update resolves multiple authorization and access control errors, including CVE-2026-71384 (CVSS 9.6) and CVE-2026-71387 (CVSS 8.8), which can lead to application denial-of-service, privilege escalation, and arbitrary code execution. Other authorization fixes include CVE-2026-71385, CVE-2026-25652, and CVE-2026-71383. As detailed in Adobe Security Bulletin APSB26-90, Adobe issued updates across supported ColdFusion platforms to remediate these flaws. The release also mitigates CVE-2026-71386 (CVSS 8.8), a cross-site scripting (XSS) vulnerability that can trigger code execution upon user interaction. Additional fixes address systemic cryptographic and input validation risks: Hard-Coded Cryptographic Key (CVE-2026-34635): Fixes key management flaws that could compromise data protection. Risky Cryptographic Algorithm (CVE-2026-48386): Resolves algorithm weaknesses that expose sensitive system memory. Improper Input Validation (CVE-2026-21279): Binds input bounds checks to prevent unexpected execution states. Remediating these arbitrary code execution flaws prevents threat actors from pivoting through enterprise applications. CVE Identifier Vulnerability Type CVSS Score Impact / Exploitation Prerequisite CVE-2026-48362 OS Command Injection 10.0 Remote unauthenticated arbitrary code execution CVE-2026-48273 Eval Injection 9.9 Authenticated arbitrary code execution (low privilege) CVE-2026-71384 Incorrect Authorization 9.6 Application Denial-of-Service (DoS) CVE-2026-71387 Incorrect Authorization 8.8 Arbitrary code execution / Security bypass CVE-2026-71386 Cross-Site Scripting (XSS) 8.8 User interaction leading to code execution CVE-2026-48440 Heap-based Buffer Overflow 8.1 Arbitrary code execution under specific conditions Adobe reports no active exploitation of these ColdFusion vulnerabilities in the wild. However, given the presence of unauthenticated RCE primitives, administrators must not delay applying Adobe security updates. Apply Software Patches: Upgrade ColdFusion 2025 to version 2025.0.12 and ColdFusion 2023 to version 2023.0.23. Restrict Administrative Portals: Ensure ColdFusion administrative interfaces are isolated from direct public internet exposure. Audit Server Logs: Inspect execution and web logs for anomalous OS commands, unusual process spawns, or unauthorized authentication patterns. [Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now Tags cyber security news Copy URL Linkedin Twitter ReddIt Telegram Guru Baranhttps://cybersecuritynews.com Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Attack News Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure Cyber Security News Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions Cyber Security News Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access Cyber Security News 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies Cyber Security News 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗