CVE-2026-48362 โ Adobe ColdFusion OS Command Injection
CVE-2026-48362 is an operating system command injection vulnerability in Adobe ColdFusion, rated CVSS 10.0. Successful exploitation allows arbitrary code execution on the server. It was fixed in ColdFusion 2025.0.12 and 2023.0.23 as part of Adobe's August 2026 security release.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-48362 |
| Type | OS command injection โ arbitrary code execution |
| Product | Adobe ColdFusion (2025.x, 2023.x) |
| CVSS | 10.0 (Critical) |
| Exploitation status | No in-the-wild exploitation reported at disclosure |
| Fixed in | ColdFusion 2025.0.12, 2023.0.23 |
Context
ColdFusion holds a long track record of internet-facing exploitation (including the CVE-2023-26360 and CVE-2023-38203 campaigns), and historically under-patched instances are a favourite initial-access target for ransomware affiliates. The August 2026 release shipped three CVSS 10.0 flaws across ColdFusion, Commerce and Campaign Classic โ see Cve 2026 71398 Adobe Campaign Incorrect Authz and Cve 2026 48273 Adobe Coldfusion Eval Injection. Organisations running legacy ColdFusion are advised to upgrade immediately or isolate instances.
Related Pages
- Cve 2026 48273 Adobe Coldfusion Eval Injection โ ColdFusion eval injection (CVSS 9.9)
- Cve 2026 71398 Adobe Campaign Incorrect Authz โ Campaign Classic flaw (CVSS 10.0)
Sources: raw/digests/Cyber-Digest-2026-08-13