CVE-2026-48362Patch(adobe / coldfusion)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch adobe coldfusion systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coldfusion

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 12 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 10 mentions (2026-08-12); latest day: 1
  • 14 total mentions across 4 days

Affected systems

Vendors
Products
coldfusion

2 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 4d
035810Mentions · 2026-08-11: 2Mentions · 2026-08-12: 10Mentions · 2026-08-19: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-12: 1Active Exploitation · 2026-08-12: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 8Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 9Technical Details · 2026-08-19: 1Technical Details · 2026-08-21: 108-1108-1208-1908-21
Signal classification4 categories
Patch
964.3%
Disclosure
321.4%
PoC
17.1%
General
17.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-112
Patch1PoC1
2026-08-1210
Disclosure1General1Patch8
2026-08-191
Disclosure1
2026-08-211
Disclosure1
Full discourse14 posts
  • Aretiq.AI@AretiqAI
    PoC

    ARETIQ Daily Vulnerability Bulletin — August 11, 2026 🔴 CRITICAL: CVE-2026-48362 (adobe/coldfusion_2025) AAS 13.8 🔴 CRITICAL: CVE-2026-71362 (adobe/adobe_commerce) AAS 13.8 — PoC available 🔴 CRITICAL: CVE-2026-72785 (craftcms/cms) AAS 13.5 — PoC available 🔴 CRITICAL: CVE-2026-72920 (seaweedfs/seaweedfs) AAS 13.1 — PoC available 🔴 CRITICAL: CVE-2026-46670 (yeswiki/yeswiki) AAS 12.4 — PoC available + 4 more CRITICAL 111 vulnerabilities — CRITICAL: 9, HIGH: 102 Full bulletin: https://aretiq.ai/bulletins/2026-08-11/

    Post summary

    The bulletin announces critical CVEs and notes that Proof of Concept code is available for several of them, but it does not provide exploitation details, patch information, or evidence of in-the-wild usage.

    010951.0K
    232 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 Adobe ColdFusion için CVSS 10.0 kritik RCE içeren güvenlik güncellemeleri yayınlandı! En kritik açık CVE-2026-48362. OS Command Injection olarak tanımlanan açık, kimlik doğrulama ve kullanıcı etkileşimi gerektirmeden uzaktan işletim sistemi komutlarının çalıştırılmasına izin veriyor. CVSS skoru 10.0! Güncellemede ayrıca CVSS 9.9 seviyesinde Eval Injection (CVE-2026-48273) ve çeşitli yetkilendirme, buffer overflow, XSS ve input validation açıkları dahil toplam 14 CVE gideriliyor. 🔴 Etkilenen sürümler: • ColdFusion 2025 -> 2025.0.11 ve öncesi • ColdFusion 2023 -> 2023.0.22 ve öncesi ✅ Güncel sürümler: • ColdFusion 2025.0.12 • ColdFusion 2023.0.23 Adobe, şu an için bu açıkların aktif olarak istismar edildiğine dair bir bilginin olmadığını belirtiyor. ColdFusion sunucuları için güncellemenin geciktirilmemesi özellikle önemli. 🔗 Adobe Security Bulletin: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.htm

    Post summary

    Adobe released critical patches for ColdFusion, addressing CVE‑2026‑48362 and 13 other vulnerabilities, with no known active exploitation reported.

    00020330
    2.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🧨 Adobe ColdFusion and Campaign Classic: Enterprise Software Under Fire CVE-2026-48362 hits Adobe ColdFusion with an OS Command Injection vulnerability scoring CVSS 10.0. While no exploit is publicly confirmed yet, ColdFusion's history as a favorite…

    Post summary

    The text announces CVE-2026-48362, an OS Command Injection flaw in Adobe ColdFusion with a CVSS 10.0 rating, noting that no exploit or patch has been disclosed.

    1000031
    80 followersView on X
  • Criminal IP@CriminalIP_US
    Disclosure

    🅰️Adobe ColdFusion CVE-2026-48362 vulnerability analysis CVE-2026-48362 is a critical Adobe ColdFusion vulnerability with a CVSS score of 10.0. It can be exploited remotely without authentication, potentially allowing attackers to execute arbitrary code on affected servers. 🔎 Criminal IP findings: • 744 Internet-exposed ColdFusion-related assets were identified via title: ColdFusion • 726 assets exposed the /CFIDE/administrator/ path associated with ColdFusion Administrator • 701 assets returned HTTP 200 responses for /CFIDE/administrator/ • Some assets directly exposed the ColdFusion Administrator interface to the public Internet Organizations should update ColdFusion to the latest patched version, identify Internet-exposed servers, and restrict unnecessary public access to administrative interfaces such as /CFIDE/administrator/. 👉 Read the full analysis: https://www.criminalip.io/knowledge-hub/blog/37257 #AdobeColdFusion #CVE202648362 #ColdFusion #ThreatIntelligence #Cybersecurity

    Post summary

    The post announces CVE-2026-48362 as a critical ColdFusion flaw with CVSS 10.0, notes exposed administrative interfaces, urges patching and access restrictions, but provides no PoC or active exploitation evidence.

    00010254
    4.9K followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    [CVE] CVE-2026-48362 [HIGH PRIORITY] #ColdFusion | Improper Neutralization of Special Elements used in an OS Comman... 🔗 https://exploitgrid.net/cve/CVE-2026-48362

    Post summary

    The post announces CVE‑2026‑48362, a high‑priority ColdFusion vulnerability involving improper neutralization of special elements in OS commands, and links to a site that likely contains a PoC.

    1000033
    30 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-17061 CVE-2026-27302 CVE-2026-45618 CVE-2026-48056 CVE-2026-48362 ..🧵👇

    Post summary

    The post merely lists five CVE identifiers without providing any additional technical, operational, or contextual information.

    1000052
    30 followersView on X
  • TECHEPAGES@techepages
    Patch

    Adobe has released patches for 50+ vulnerabilities, including critical flaws in ColdFusion (CVE-2026-48362, CVE-2026-48273, CVE-2026-71384) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, CVE-2026-48381). These issues could enable arbitrary code execution or DoS. Commerce updates also address privilege escalation (CVE-2026-71362). With Priority 1 ratings, immediate patching is strongly advised.

    Post summary

    Adobe has issued patches for over 50 vulnerabilities, including critical ColdFusion and Campaign Classic CVEs that can lead to arbitrary code execution, DoS, and privilege escalation; immediate patching is strongly advised.

    0001060
    38 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #ColdFusion ColdFusion 2025 2025.0.12 ColdFusion 2023 2023.0.23 ・CVE-2026-48362(CVSS 10.0) ・CVE-2026-48273(〃 9.9) ・CVE-2026-21279 ・CVE-2026-25652 ・CVE-2026-34635 ・CVE-2026-48386 ・CVE-2026-48440 ・CVE-2026-71384 つづく…

    Post summary

    The tweet announces that newer ColdFusion releases address several CVEs, indicating patch availability and providing associated CVSS scores.

    1000051
    90 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #adobeupdate #adobe #ColdFusion Adobe から,ColdFusion で更新をリリース. 適用優先度「1」,緊急度には「Critical」 11 件(うち CVSS 10.0 1 件) ・CVE-2026-48362 Important 4 件が含まれる. https://x.com/kawn2020/status/2087447033909313546

    Post summary

    Adobe released a ColdFusion security update covering CVE-2026-48362 and other critical issues, with a CVSS score of 10.0, but no PoC, exploit, or active exploitation details were shared.

    1000045
    90 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-48362: Adobe ColdFusion Command Injection (CVSS 10.0) — Detection and … "Adobe has shipped an out-of-band security update addressing multiple critical vulnerabilities…" 🔗 https://securityarsenal.com/blog/cve-2026-48362-adobe-coldfusion-command-injection-cvss-100-detection-and-remediation-guide #CyberSecurity #ThreatIntel #critical #zeroday #cve

    Post summary

    The tweet announces CVE-2026-48362, a critical command‑injection flaw in Adobe ColdFusion, and notes that Adobe has already released an out‑of‑band patch. No PoC, exploit code, or reports of active exploitation are mentioned.

    0000065
    23 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Adobe ColdFusion Unauthenticated OS Command Injection RCE (CVE-2026-48362) Adobe ColdFusion (2025 through 2025.0.11 and 2023 through 2023.0.22) contains an OS command injection flaw that allows arbitrary code execution. It requires no authentication and no user interaction, is scope-changing, and has full impact on confidentiality, integrity, and availability, scoring the maximum CVSS 10.0. CISA rates it as automatable, and ColdFusion has a long history of in-the-wild exploitation, so internet-facing instances should be treated as high risk and patched immediately. CVSS 10.0. 👉Upgrade to ColdFusion 2025.0.12 or 2023.0.23 per Adobe advisory APSB26-90.

    Post summary

    Adobe announced a critical OS command injection RCE in ColdFusion (CVE-2026-48362) and urges users to patch immediately using the latest releases from Adobe advisory APSB26-90, citing an in‑the‑wild exploitation history.

    0000076
    288 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · 🚨 Vulnerabilities · 11 August 2026 🎯 Adobe patches multiple critical ColdFusion flaws — one rated CVSS 10 Adobe released fixes for more than 50 vulnerabilities across its products. ColdFusion alone received fixes for 15 flaws, including CVE-2026-48362, a CVSS 10 OS command-injection vulnerability, while Campaign Classic also received patches for critical arbitrary-code-execution issues. Adobe recommends rapid patching of the highest-priority flaws. 🔗 Source: Adobe / SecurityWeek #Adobe #ColdFusion #Vulnerability #RCE #CyberSecurity

    Post summary

    Adobe has issued patches for 15 ColdFusion flaws, including CVE-2026-48362, a CVSS 10 OS command‑injection vulnerability, and urges rapid patching—no PoC, exploit code, or active exploitation is reported.

    0000042
    42 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🔥 Adobe patches multiple CVSS 10.0 vulnerabilities Adobe released fixes for 50+ vulnerabilities across its products. Among the most severe: 🔴 ColdFusion CVE-2026-48362 — CVSS 10.0 🔴 Campaign Classic CVE-2026-71398 — CVSS 10.0 🔴 Campaign Classic CVE-2026-27302 — CVSS 10.0 Potential impact includes arbitrary code execution and denial of service. 📅 August 11, 2026 🔎 Source: Adobe / SecurityWeek. #Adobe #ColdFusion #CVE #CyberSecurity #PatchNow

    Post summary

    Adobe has released security patches for over 50 critical CVSS 10.0 vulnerabilities, including CVE-2026-48362 and two CVE-2026-71398/27302, with impacts of arbitrary code execution and denial of service.

    0000038
    42 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🔥 Adobe ColdFusion hit with CVSS 10 OS Command Injection — CVE-2026-48362. No auth, no interaction, network-accessible RCE. If you're running ColdFusion, patch now. #cybersecurity #ciso #cto #vulnerabilities #msp #mssp https://secalerts.co/vulnerability/CVE-2026-48362?utm_campaign=x https://t.co/c2SXIoBeK1

    Post summary

    Adobe ColdFusion CVE-2026-48362 is a critical OS command injection (CVSS 10) that requires no authentication and is network‑accessible. Urgent patching is advised; no PoC or active exploitation has been reported.

    00000244
    877 followersView on X
CPE platform detail35 entries

35 of 35 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2023--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--
Appadobecoldfusion2025--

Explore more