
ColdFusion | Improper Input Validation (CWE-20) CVE: CVE-2026-27282 PT ID: PT-2026-32919 Vendor: Adobe Product: ColdFusion CVSS: 7.5 Credits: n/a Description: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27282 • https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html #dbugs_vuln
Post summary
Adobe’s ColdFusion 2023.18 and earlier are vulnerable to Improper Input Validation (CVE‑2026‑27282) with a CVSS of 7.5, and a vendor advisory is available for remediation.

