type: cve ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [cve, adobe, coldfusion, eval-injection, remote-code-execution] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, education] ยท au_impact: true
CVE-2026-48273 โ Adobe ColdFusion Eval Injection
CVE-2026-48273 is an eval injection vulnerability in Adobe ColdFusion, rated CVSS 9.9. Successful exploitation could lead to arbitrary code execution on the server. It was fixed in ColdFusion 2025.0.12 and 2023.0.23 in Adobe's August 2026 security release.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-48273 |
| Type | Eval injection โ arbitrary code execution |
| Product | Adobe ColdFusion (2025.x, 2023.x) |
| CVSS | 9.9 (Critical) |
| Exploitation status | No in-the-wild exploitation reported at disclosure |
| Fixed in | ColdFusion 2025.0.12, 2023.0.23 |
Context
The August 2026 release closed an unusually severe ColdFusion batch โ two arbitrary-code-execution flaws at CVSS 10.0 and 9.9 respectively, plus an application DoS via incorrect authorisation (CVE-2026-71384). Given ColdFusion's history as an initial-access vector, the fixes should be deployed promptly on internet-facing instances. For AU/NZ contexts this reinforces Essential Eight application-patching expectations.
Related Pages
- Cve 2026 48362 Adobe Coldfusion Cmd Injection โ ColdFusion OS command injection (CVSS 10.0)
- Cve 2026 71398 Adobe Campaign Incorrect Authz โ Campaign Classic incorrect authorisation (CVSS 10.0)
Sources: raw/digests/Cyber-Digest-2026-08-13