CVE-2026-34619Disclosure(adobe / coldfusion)

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch adobe coldfusion systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-15)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 204-1404-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-152
Disclosure1Patch1
Full discourse3 posts
  • dbugs@ptdbugs
    Patch

    ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CVE: CVE-2026-34619 PT ID: PT-2026-32934 Vendor: Adobe Product: ColdFusion CVSS: 7.7 Credits: n/a Description: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34619 • https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html #dbugs_vuln

    Post summary

    The text announces the ColdFusion CVE-2026-34619, details its path traversal flaw, and references a vendor advisory with a patch.

    0000065
    797 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34619 ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that c… https://www.cve.org/CVERecord?id=CVE-2026-34619

    Post summary

    The post announces CVE-2026-34619 as a path traversal vulnerability affecting specified ColdFusion versions, providing basic technical details but no evidence of PoC, exploit, or mitigation information.

    0000078
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-34619 | Adobe ColdFusion | Path Traversal Description ColdFusion versions 2023.18, 2025.6 and earlier suffer from a path traversal vulnerability that allows unauth attackers to bypass security restrictions and access unauthorized files or directories outside intended paths by sending crafted requests; no user interaction is required. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Adobe ColdFusion Affected Version: >= 0 and <= 2025.6 Sources Vendor: https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html

    Post summary

    Adobe ColdFusion versions up to 2025.6 are vulnerable to unauthenticated path traversal, but a patch is available and no public PoC or active exploitation has been reported.

    0000082
    8 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more