Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code
Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability. Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent. Adobe ColdFusion Flaws […] The post Critical Adobe ColdFusion Vulnerabilities Allow Attackers to E
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code
By Guru Baran
August 12, 2026
Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code
Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability.
Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent.
Adobe ColdFusion Flaws Enable Code Execution
The most alarming flaw resolved in this batch is CVE-2026-48362, an unauthenticated OS command injection vulnerability with a maximum CVSS base score of 10.0.
The flaw allows remote, unauthenticated attackers to execute arbitrary operating system commands on vulnerable ColdFusion servers without any user interaction.
On internet-exposed servers, this grants attackers an immediate path to full host takeover. In addition to command injection, Adobe resolved CVE-2026-48273, an eval injection flaw rated 9.9 on the CVSS scale.
Although exploiting this bug requires low-level privileges, an authenticated user could still leverage it to run arbitrary code. Another critical fix addresses CVE-2026-48440 (CVSS 8.1), a heap-based buffer overflow that opens additional execution vectors.
Addressing these critical Adobe vulnerabilities is essential for preventing host compromise across public web services.
The update resolves multiple authorization and access control errors, including CVE-2026-71384 (CVSS 9.6) and CVE-2026-71387 (CVSS 8.8), which can lead to application denial-of-service, privilege escalation, and arbitrary code execution.
Other authorization fixes include CVE-2026-71385, CVE-2026-25652, and CVE-2026-71383.
As detailed in Adobe Security Bulletin APSB26-90, Adobe issued updates across supported ColdFusion platforms to remediate these flaws.
The release also mitigates CVE-2026-71386 (CVSS 8.8), a cross-site scripting (XSS) vulnerability that can trigger code execution upon user interaction.
Additional fixes address systemic cryptographic and input validation risks:
Hard-Coded Cryptographic Key (CVE-2026-34635): Fixes key management flaws that could compromise data protection.
Risky Cryptographic Algorithm (CVE-2026-48386): Resolves algorithm weaknesses that expose sensitive system memory.
Improper Input Validation (CVE-2026-21279): Binds input bounds checks to prevent unexpected execution states.
Remediating these arbitrary code execution flaws prevents threat actors from pivoting through enterprise applications.
CVE Identifier Vulnerability Type CVSS Score Impact / Exploitation Prerequisite
CVE-2026-48362 OS Command Injection 10.0 Remote unauthenticated arbitrary code execution
CVE-2026-48273 Eval Injection 9.9 Authenticated arbitrary code execution (low privilege)
CVE-2026-71384 Incorrect Authorization 9.6 Application Denial-of-Service (DoS)
CVE-2026-71387 Incorrect Authorization 8.8 Arbitrary code execution / Security bypass
CVE-2026-71386 Cross-Site Scripting (XSS) 8.8 User interaction leading to code execution
CVE-2026-48440 Heap-based Buffer Overflow 8.1 Arbitrary code execution under specific conditions
Adobe reports no active exploitation of these ColdFusion vulnerabilities in the wild. However, given the presence of unauthenticated RCE primitives, administrators must not delay applying Adobe security updates.
Apply Software Patches: Upgrade ColdFusion 2025 to version 2025.0.12 and ColdFusion 2023 to version 2023.0.23.
Restrict Administrative Portals: Ensure ColdFusion administrative interfaces are isolated from direct public internet exposure.
Audit Server Logs: Inspect execution and web logs for anomalous OS commands, unusual process spawns, or unauthorized authentication patterns.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Tags
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Attack News
Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure
Cyber Security News
Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions
Cyber Security News
Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
Cyber Security News
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Cyber Security News
2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?