CVE-2026-48281Disclosure(adobe / coldfusion)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe coldfusion systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 4 mentions (2026-06-30); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-06-30: 4Mentions · 2026-07-01: 2Mentions · 2026-07-02: 1Mentions · 2026-07-19: 2Mentions · 2026-07-27: 1Patch / Workaround · 2026-06-30: 2Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-27: 1Technical Details · 2026-06-30: 3Technical Details · 2026-07-01: 2Technical Details · 2026-07-02: 1Technical Details · 2026-07-27: 106-3007-0107-0207-1907-27
Signal classification2 categories
Disclosure
550.0%
Patch
550.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-06-304
Disclosure2Patch2
2026-07-012
Patch2
2026-07-021
Disclosure1
2026-07-192
Disclosure2
2026-07-271
Patch1
Full discourse10 posts
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin announces a list of 31 Adobe ColdFusion CVEs with emergency and critical severity ratings but lacks detailed technical info, PoC, exploitation reports or patch guidance.

    010111689
    227 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Adobe ColdfusionでCVSSスコア10の脆弱性6件が修正。6/30に11件の脆弱性が修正されたうちの一部。無制限のファイルアップロードCVE-2026-48276及びCVE-2026-48283、入力検証不備CVE-2026-48277、CVE-2026-48281、CVE-2026-48316、パストラバーサルCVE-2026-48282。優先度P1。 https://securityonline.info/adobe-coldfusion-vulnerabilities-apsb26-68/

    Post summary

    Adobe announced patches for six high‑severity CVEs, including file upload and path traversal flaws, on June 30.

    01051870
    7.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されている。 https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/

    Post summary

    Adobe has released patches for seven critical ColdFusion and Campaign Classic CVEs with a CVSS score of 10; the post confirms the availability of updates but does not mention exploits, PoC, or ongoing attacks.

    102212.1K
    7.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-48282: ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277…

    Post summary

    The bulletin announces several new Adobe ColdFusion CVEs with an emergency warning, but provides no additional technical details, PoC, or patch information.

    1000045
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3

    Post summary

    The text issues an emergency alert about four new Adobe ColdFusion CVEs affecting AAS 16.3, but provides no additional technical or remedial details.

    1000039
    326 followersView on X
  • CyberTLDR@CyberTLDR
    Disclosure

    2/3 The ColdFusion CVEs cover unrestricted file uploads (CVE-2026-48276, CVE-2026-48283), improper input validation (CVE-2026-48277, CVE-2026-48281), and path traversal (CVE-2026-48282). All rated 10.0 and all lead to remote code execution. #Adobe #PatchTuesday #AppSec

    Post summary

    The tweet announces five new ColdFusion CVEs, detailing their categories, a CVSS score of 10.0, and noting they all lead to remote code execution.

    1000085
    17 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-48281: Adobe ColdFusion Improper Input Validation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04qT06N0

    Post summary

    The article focuses on Adobe ColdFusion's improper input validation flaw (CVE‑2026‑48281) and advises readers on how to mitigate the issue, likely through vendor patches.

    0000036
    32 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by critical security vulnerabilities that can be exploited by attackers without privileges to gain remote code execution on unpatched systems. - CVE-2026-48276 - CVE-2026-48277 - CVE-2026-48281 - CVE-2026-48316 - CVE-2026-48282 Resolution for Cold Fusion lies in updating CF 2023 to Update 21 and CF 2025 to Update 10.

    Post summary

    The text highlights critical CVEs in Adobe ColdFusion affecting remote code execution, provides specific CS updates as patches, and offers basic technical details without evidence of active exploitation or PoC.

    0000072
    22 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🔥 Adobe ColdFusion hit with a CVSS 10 critical RCE. CVE-2026-48281 affects versions 2025.9, 2023.20 and earlier via improper input validation. Patch now. #ColdFusion #cybersecurity https://secalerts.co/vulnerability/CVE-2026-48281?utm_campaign=x https://t.co/DGmD7C0xwy

    Post summary

    Adobe ColdFusion CVE-2026-48281 is a critical RCE (CVSS 10) impacting several versions; the alert stresses that a patch is now available.

    0000096
    847 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48281 Improper Input Validation Remote Code Execution in Adobe ColdFusi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48281 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A tweet announces CVE-2026-48281, an Adobe ColdFusion vulnerability that allows remote code execution via improper input validation, and provides a link to detailed information and alert subscription.

    00000105
    4.1K followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more