CVE-2026-48316Patch(adobe / coldfusion)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adobe coldfusion systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-07-01); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-06-30: 1Mentions · 2026-07-01: 2Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-13: 1Mentions · 2026-07-27: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 106-3007-0107-0607-0707-1307-27
Signal classification3 categories
Patch
457.1%
Disclosure
228.6%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-301
Patch1
2026-07-012
Patch2
2026-07-061
Patch1
2026-07-071
Disclosure1
2026-07-131
Disclosure1
2026-07-271
General1
Full discourse7 posts
  • kokumօtօ@__kokumoto
    Patch

    Adobe ColdfusionでCVSSスコア10の脆弱性6件が修正。6/30に11件の脆弱性が修正されたうちの一部。無制限のファイルアップロードCVE-2026-48276及びCVE-2026-48283、入力検証不備CVE-2026-48277、CVE-2026-48281、CVE-2026-48316、パストラバーサルCVE-2026-48282。優先度P1。 https://securityonline.info/adobe-coldfusion-vulnerabilities-apsb26-68/

    Post summary

    Adobe ColdFusion vulnerabilities identified by CVE-2026-48276 through CVE-2026-48316 have been patched as of June 30, with a priority P1 advisory announced and no mention of active exploitation or exploit code.

    01051870
    7.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    AdobeがColdFusionでCVSSスコア10の脆弱性6件を修正。CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282。なお、今後定例更新は月2回になるとのこと。Campaign ClassicでもCVSSスコア10のCVE-2026-48286が修正されている。 https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/

    Post summary

    Adobe released patches for seven CVSS 10 ColdFusion and Campaign Classic vulnerabilities, with future updates scheduled to occur twice a month.

    102212.1K
    7.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-48316 - CRITICAL: Unauthenticated RCE in #ColdFusion. #CVSS 10.0. No patch available. Immediate mitigation required. https://www.valtersit.com/cve/CVE-2026-48316 #CVEAlert #infosec #devsecops #devops #developers #sysadmin #DevelopingUgandaTogether #git #github #gitlab #linux #readteam #bluetem

    Post summary

    The tweet announces a critical unauthenticated RCE (CVE‑2026‑48316) in ColdFusion with a CVSS score of 10.0, notes that no patch exists and urges immediate mitigation, but provides no exploit or PoC details.

    0001068
    974 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-48316 — CVSS 10/10 ██████████ ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/HSmv7DfV2f

    Post summary

    ColdFusion versions prior to 2025.9 are vulnerable to CVE-2026-48316 (CVSS 10/10) through Improper Input Validation, and a patch is now available.

    10000107
    64 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-48316: Adobe ColdFusion Improper Input Validation - What It Means for Your Business and How to Respond https://hubs.li/Q04qV9s70

    Post summary

    The provided text only references CVE-2026-48316 in the title of an article, offering no technical, exploitation, or mitigation details.

    0000027
    32 followersView on X
  • NCA Azerbaijan@NCAAzerbaijan
    Disclosure

    "Adobe ColdFusion" platformasında uzaqdan kod icrası riski (CVE-2026-48316) aşkarlanıb. #MKA #NCA #MilliCERT #Cybersecurity #Kibertəhlükəsizlik #Xəbərdarlıq https://t.co/zU05htum2D

    Post summary

    The post announces the discovery of CVE-2026-48316, a remote code‑execution vulnerability affecting Adobe ColdFusion, without additional details or exploit information.

    00000325
    136 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe ColdFusion versions 2025.9, 2023.20 and earlier are affected by critical security vulnerabilities that can be exploited by attackers without privileges to gain remote code execution on unpatched systems. - CVE-2026-48276 - CVE-2026-48277 - CVE-2026-48281 - CVE-2026-48316 - CVE-2026-48282 Resolution for Cold Fusion lies in updating CF 2023 to Update 21 and CF 2025 to Update 10.

    Post summary

    Adobe ColdFusion 2023.20 and 2025.9 (and earlier) suffer critical, privilege‑less RCE vulnerabilities (CVE‑2026‑48276, ‑48277, ‑48281, ‑48316, ‑48282). Updated patches – CF 2023 Update 21 and CF 2025 Update 10 – are the recommended remediation.

    0000072
    22 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more