CVE-2026-48362
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-48362 is a critical OS Command Injection vulnerability (CWE-78) in Adobe ColdFusion that allows unauthenticated remote attackers to execute arbitrary code in the context of the current user. It affects Adobe ColdFusion 2023 (all updates through 2023 Update 22) and ColdFusion 2025 (all updates through 2025 Update 11). Adobe disclosed and patched the vulnerability on August 11, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) with changed scope, reflecting the maximum possible severity (Adobe Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning user-supplied input is passed to OS-level command execution without adequate sanitization or escaping. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity — making it fully automatable. The changed scope indicator suggests that successful exploitation can affect resources beyond the ColdFusion application itself, potentially impacting the underlying host operating system. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Adobe Advisory, Feedly).

Impact

Successful exploitation grants an unauthenticated remote attacker the ability to execute arbitrary OS commands in the context of the ColdFusion service account, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could read sensitive data, modify or delete files, install malware or backdoors, and potentially pivot laterally to other systems on the network. The changed scope means the impact extends beyond the ColdFusion process itself to the underlying host and potentially adjacent systems (Adobe Advisory, The Hacker News).

Exploitability

As of the time of this report, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). However, the vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 0.021 (2.1%), reflecting a currently low but non-trivial probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been reported at this time. Detection plugins are available via Nessus (plugin 335158) and Qualys (plugin 532147) (Feedly).

Mitigation and workarounds

Adobe has released security updates addressing this vulnerability: ColdFusion 2025 users should update to Update 12 (version 2025.0.12 or later), and ColdFusion 2023 users should update to Update 23 (version 2023.0.23 or later). Adobe urges immediate patching given the critical, unauthenticated nature of the vulnerability. As a general hardening measure, restrict network access to ColdFusion administrative interfaces and apply the principle of least privilege to the ColdFusion service account (Adobe Advisory).

Community reactions

Adobe's August 2026 patch release, which included CVE-2026-48362 alongside two other CVSS 10.0 ColdFusion flaws, received significant media attention. SecurityWeek and The Hacker News both urged immediate patching, with The Hacker News noting that Adobe patched "three CVSS 10.0 ColdFusion" vulnerabilities in a single release (SecurityWeek, The Hacker News). CIS issued an advisory noting that multiple Adobe product vulnerabilities could allow arbitrary code execution (CIS Advisory). Community discussion on Reddit and social media platforms highlighted the severity and the need for rapid response given ColdFusion's history of being targeted by threat actors.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71384CRITICAL9.6
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71387HIGH8.8
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71386HIGH8.8
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-48440HIGH8.1
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71383HIGH7.3
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management