CVE-2026-27305Patch(adobe / coldfusion)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe coldfusion systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-07-31: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 2Technical Details · 2026-07-31: 104-1404-1507-31
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-141
Patch1
2026-04-152
Disclosure2
2026-07-311
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-27305 CVSS 8.6 - Path Traversal in Adobe ColdFusion 2023.18, 2025.6 & earlier. Remote attackers can read arbitrary files without authentication. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/JWL5lSJtkb

    Post summary

    High‑severity CVE‑2026‑27305, a path‑traversal flaw in Adobe ColdFusion, allows unauthenticated file reads; urgent patching is advised.

    0000058
    99 followersView on X
  • dbugs@ptdbugs
    Disclosure

    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CVE: CVE-2026-27305 PT ID: PT-2026-32921 Vendor: Adobe Product: ColdFusion CVSS: 8.6 Credits: n/a Description: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27305 • https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html #dbugs_vuln

    Post summary

    Adobe ColdFusion CVE‑2026‑27305 is disclosed as a path traversal flaw allowing arbitrary file reads without user interaction, rated CVSS 8.6.

    0000073
    797 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27305 ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that c… https://www.cve.org/CVERecord?id=CVE-2026-27305

    Post summary

    The message announces CVE-2026-27305, a Path Traversal flaw impacting ColdFusion versions 2023.18, 2025.6 and earlier, and links to the official CVE record.

    0000082
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-27305 | Adobe ColdFusion | Path Traversal Description ColdFusion versions 2023.18, 2025.6 and earlier suffer from a path traversal vulnerability (CWE-22) allowing unauth attackers to read arbitrary files outside the restricted directory via crafted pathnames, potentially exposing sensitive data without user interaction. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Adobe ColdFusion Affected Version: >= 0 and <= 2025.6 Sources Vendor: https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html

    Post summary

    Adobe ColdFusion CVE-2026-27305 is a high‑severity path traversal flaw with an official patch available, but no public PoC, exploit code, or evidence of active exploitation has been disclosed.

    0000074
    8 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more