CVE-2026-48277Patch(adobe / coldfusion)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe coldfusion systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked 7d ago at 4 mentions (2026-07-01); latest day: 1
  • 14 total mentions across 9 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 9d
01234Mentions · 2026-06-30: 2Mentions · 2026-07-01: 4Mentions · 2026-07-02: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Mentions · 2026-07-13: 1Mentions · 2026-07-19: 2Mentions · 2026-07-26: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 3Patch / Workaround · 2026-07-26: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 3Technical Details · 2026-07-02: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-26: 106-3007-0107-0207-0807-0907-1007-1307-1907-26
Signal classification3 categories
Patch
535.7%
Disclosure
535.7%
General
428.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-06-302
General1Patch1
2026-07-014
Disclosure1Patch3
2026-07-021
Disclosure1
2026-07-081
Disclosure1
2026-07-091
General1
2026-07-101
General1
2026-07-131
General1
2026-07-192
Disclosure2
2026-07-261
Patch1
Full discourse14 posts
  • Aretiq.AI@AretiqAI
    General

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin enumerates 31 emergency, critical, and high‑severity CVEs from Adobe and IBM, but provides no PoC, exploitation details, patch info, or technical specifics.

    010111689
    227 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されている。 https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/

    Post summary

    Adobe announced patches for seven high‑severity ColdFusion CVEs, with future updates scheduled twice a month.

    102212.1K
    7.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Adobe ❗ CVE-2026-48282 ❗ CVE-2026-48277 ❗ CVE-2026-48276 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-adobe-6/ https://t.co/OikXx2L4Fk

    Post summary

    The tweet merely lists three Adobe CVEs and points to an external link for more information, without providing any technical details, PoC, exploit code, or mitigation information.

    00020289
    6.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-48277 — CVSS 10/10 ██████████ ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/UecbxMcikx

    Post summary

    The tweet announces a critical CVE (CVE-2026-48277) affecting ColdFusion 2025.9 and earlier, highlighting Improper Input Validation with a CVSS score of 10/10, and urges users to apply the patch immediately.

    11000134
    63 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-48282: ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277…

    Post summary

    The bulletin issues emergency alerts for several CVEs affecting Adobe ColdFusion 16.3, but it provides no technical details, proof‑of‑concepts, exploit code, active exploitation evidence, or patch information.

    1000045
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3

    Post summary

    The tweet serves as an emergency announcement of four new Adobe ColdFusion (AAS 16.3) CVEs, without providing additional technical details, exploits, or mitigation information.

    1000039
    326 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Adobe ColdFusion 2025/2023 緊急アップデート:RCE などの深刻な 11件の脆弱性に対応 https://iototsecnews.jp/2026/07/01/adobe-coldfusion-critical-vulnerabilities-let-attackers-execute-arbitrary-code/ Adobe ColdFusion における、外部からの入力やファイルの不適切な取り扱いが、一連の問題の原因となっています。具体的には、制限のないファイルアップロードが可能な CVE-2026-48276 や CVE-2026-48283 、入力の検証が不十分な CVE-2026-48277 などの欠陥があります。また、不正なファイル読み込みにつながるパス・トラバーサルの CVE-2026-48282 や、不適切な入力検証による CVE-2026-48313 なども深刻な影響を及ぼします。これらの原因により、未認証の第三者が、サーバを完全に制御する可能性があります。ご利用のチームは、ご注意ください。 #Adobe #ColdFusion #CVE202648276 #CVE202648277 #CVE202648281 #CVE202648282 #CVE202648283 #CVE202648307 #CVE202648313 #CVE202648314 #CVE202648315 #CVE202648316 #Vulnerability

    Post summary

    The post announces an emergency update for Adobe ColdFusion that addresses 11 critical CVEs capable of enabling remote code execution, detailing the nature of each vulnerability but providing no PoC, exploit code, or evidence of active exploitation.

    01000188
    500 followersView on X
  • CyberTLDR@CyberTLDR
    Disclosure

    2/3 The ColdFusion CVEs cover unrestricted file uploads (CVE-2026-48276, CVE-2026-48283), improper input validation (CVE-2026-48277, CVE-2026-48281), and path traversal (CVE-2026-48282). All rated 10.0 and all lead to remote code execution. #Adobe #PatchTuesday #AppSec

    Post summary

    The tweet announces multiple ColdFusion CVEs with detailed classification and CVSS rating, highlighting their remote code execution impact, but provides no PoC, exploit code, or patch information.

    1000085
    17 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-48277: Adobe ColdFusion Improper Input Validation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04qMRfv0

    Post summary

    The article focuses on Adobe ColdFusion's improper input validation vulnerability (CVE-2026-48277), detailing its technical nature and providing patch and mitigation guidance for affected businesses.

    0000043
    32 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 45% of vulnerabilities from past week, CVE-2026-48277 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE‑2026‑48277 has attracted a surprising number of articles but offers no technical detail, remediation, or exploitation evidence.

    0000047
    74 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 38% of vulnerabilities from past week, CVE-2026-48277 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet notes that CVE‑2026‑48277 has many online reports but offers no technical details, exploit code, or patch information.

    0000053
    74 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by critical security vulnerabilities that can be exploited by attackers without privileges to gain remote code execution on unpatched systems. - CVE-2026-48276 - CVE-2026-48277 - CVE-2026-48281 - CVE-2026-48316 - CVE-2026-48282 Resolution for Cold Fusion lies in updating CF 2023 to Update 21 and CF 2025 to Update 10.

    Post summary

    Adobe ColdFusion versions listed contain critical RCE vulnerabilities that can be mitigated by updating to the specified newer releases.

    0000072
    22 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 CRITICAL: Adobe ColdFusion 3-CVE Cluster — CVSS 10.0 + 8.8 CVE-2026-48276: Unrestricted upload RCE (10.0) CVE-2026-48277: Input validation RCE (10.0) CVE-2026-48307: Reflected XSS (8.8) 🔗 https://threataft.com/articles/adobe-coldfusion-cve-2026-48276-48277-48307 #CyberSecurity #ThreatIntel #infosec #ColdFusion

    Post summary

    The post announces three critical Adobe ColdFusion CVEs with details on their impact and severity, but it offers no PoC, exploit, or patch information.

    00000106
    31 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧊 Adobe ColdFusion hit with a CVSS 10 RCE. No auth, no interaction needed. Versions 2025.9, 2023.20 and earlier are exposed via improper input validation. CVE-2026-48277 demands immediate patching. https://secalerts.co/vulnerability/CVE-2026-48277?utm_campaign=x https://t.co/qET3a5Ku7J

    Post summary

    Adobe ColdFusion suffers from a critical CVE-2026-48277 (CVSS 10 RCE) affecting multiple versions, requiring immediate patching.

    0000099
    847 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more