Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [cve, adobe, coldfusion, command-injection, remote-code-execution, cvss-10] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, education] ยท au_impact: true

CVE-2026-48362 โ€” Adobe ColdFusion OS Command Injection

CVE-2026-48362 is an operating system command injection vulnerability in Adobe ColdFusion, rated CVSS 10.0. Successful exploitation allows arbitrary code execution on the server. It was fixed in ColdFusion 2025.0.12 and 2023.0.23 as part of Adobe's August 2026 security release.

Vulnerability Details

Attribute Detail
CVE CVE-2026-48362
Type OS command injection โ†’ arbitrary code execution
Product Adobe ColdFusion (2025.x, 2023.x)
CVSS 10.0 (Critical)
Exploitation status No in-the-wild exploitation reported at disclosure
Fixed in ColdFusion 2025.0.12, 2023.0.23

Context

ColdFusion holds a long track record of internet-facing exploitation (including the CVE-2023-26360 and CVE-2023-38203 campaigns), and historically under-patched instances are a favourite initial-access target for ransomware affiliates. The August 2026 release shipped three CVSS 10.0 flaws across ColdFusion, Commerce and Campaign Classic โ€” see Cve 2026 71398 Adobe Campaign Incorrect Authz and Cve 2026 48273 Adobe Coldfusion Eval Injection. Organisations running legacy ColdFusion are advised to upgrade immediately or isolate instances.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13