CVE-2026-27304Disclosure(adobe / coldfusion)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-15); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-14: 2Mentions · 2026-04-15: 3Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 3Technical Details · 2026-04-17: 104-1404-1504-17
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-153
Disclosure2Patch1
2026-04-171
Patch1
Full discourse6 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The excerpt enumerates April 2026 security advisories across multiple vendors, providing technical details of each CVE but lacking evidence of exploits, PoCs, or patches.

    000321.4K
    11.7K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🎨 منتجات Adobe: 🎥 منتج Adobe Connect: التقييم: 9.6 | (CVE-2026-27303, 34615) ⚠️ تحديثات طارئة لسد ثغرات (Deserialization RCE). ❄️ منتج Adobe ColdFusion: التقييم: 9.3 | (CVE-2026-27304) ⚠️ تجاوز التحقق من المدخلات (Input Validation Bypass).

    Post summary

    The post announces CVE-2026-27303 and CVE-2026-27304 affecting Adobe Connect and ColdFusion, provides technical details, and alerts that emergency updates are available, but does not mention any PoC, exploit code, or active exploitation.

    100011.6K
    48.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-27304 — CVSS 9.3/10 █████████░ ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/TWpYM00jyg

    Post summary

    Tweet highlights a critical input validation flaw in ColdFusion and urges readers to apply the provided patch, but offers no PoC or exploitation details.

    1000039
    23 followersView on X
  • dbugs@ptdbugs
    Disclosure

    ColdFusion | Improper Input Validation (CWE-20) CVE: CVE-2026-27304 PT ID: PT-2026-32920 Vendor: Adobe Product: ColdFusion CVSS: 9.3 Credits: n/a Description: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27304 • https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html #dbugs_vuln

    Post summary

    The post announces Adobe ColdFusion versions up to 2025.6 are vulnerable to CVE‑2026‑27304, an Improper Input Validation flaw with a CVSS of 9.3 that can lead to arbitrary code execution without user interaction. No PoC, exploit tool, or active exploitation claims are made.

    0000081
    797 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27304 ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the contex… https://www.cve.org/CVERecord?id=CVE-2026-27304

    Post summary

    CVE-2026-27304 is an improper input validation flaw in ColdFusion that could enable arbitrary code execution, with no information on exploitation, patches, or PoCs provided.

    0000082
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27304: ColdFusion | Improper Input Vali... Zero-interaction RCE in ColdFusion with 9.3 CVSS - input validation bypass means instant shells on corporate web apps s... https://zerodaysignal.com/vulnerability/CVE-2026-27304 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A zero‑interaction remote code execution flaw in ColdFusion (CVE‑2026‑27304), scored 9.3 on CVSS, is disclosed, enabling instant shells through an input‑validation bypass.

    0000067
    218 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more