Adobe issued urgent ColdFusion updates after multiple severe vulnerabilities were disclosed across ColdFusion 2025 and 2023, including several flaws that can lead to arbitrary code execution. The most serious newly listed issue, CVE-2026-48362, is an unauthenticated OS command injection bug rated CVSS 10.0, while CVE-2026-48273 was rated 9.9 for eval injection. Additional high-severity flaws include CVE-2026-71387 (incorrect authorization, CVSS 8.8) and CVE-2026-71386 (cross-site scripting, CVSS 8.8), alongside other issues affecting authorization, memory safety, denial of service, and sensitive memory exposure. Adobe said affected versions include ColdFusion 2025 up to 2025.0.11 and ColdFusion 2023 up to 2023.0.22, and directed customers to upgrade to 2025.0.12 or 2023.0.23.
The warnings follow earlier reports that attackers rapidly exploited at least one maximum-severity ColdFusion flaw, CVE-2026-48282, a path traversal vulnerability that can enable arbitrary code execution without user interaction. Researchers said exploitation began within hours of public disclosure, and Shadowserver data cited 775 internet-exposed ColdFusion instances, highlighting the reachable attack surface. Adobe said it had not observed active exploitation of the latest August issues, but advised administrators to patch immediately, restrict access to the administrative network zone and portal, limit network exposure, monitor logs for unauthorized access attempts, and accelerate remediation as ColdFusion remains a high-value target.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Adobe modified the CVE-2026-71387 record on August 11, 2026, changing the affected product default status from unaffected to affected. The update also reflected the Adobe advisory and product ranges for ColdFusion 2025 and 2023.
On August 11, 2026, Adobe added the initial CVE record for CVE-2026-71387, an incorrect authorization vulnerability in ColdFusion. The flaw can lead to arbitrary code execution without user interaction and affects ColdFusion 2025 through 2025.0.11 and 2023 through 2023.0.22.
A new CVE entry for CVE-2026-71386 was received from Adobe's PSIRT on August 11, 2026. The record describes a high-severity ColdFusion cross-site scripting flaw that can lead to arbitrary code execution in the current user's context and affects ColdFusion 2025 through 2025.0.11 and 2023 through 2023.0.22.
Security researchers reported that CVE-2026-48282 was being targeted within hours of becoming public. The flaw affects Adobe ColdFusion and can enable arbitrary code execution via path traversal.
On June 30, Adobe released security bulletin APSB26-68 for ColdFusion, fixing 11 vulnerabilities, including six rated CVSS 10.0. The bulletin included CVE-2026-48282, a path traversal flaw that can lead to arbitrary code execution without user interaction.
Adobe said in June that it would move from monthly to twice-monthly publication of security advisories. The company linked the change to faster vulnerability discovery and a shrinking exploitation window driven by AI.
Adobe issued urgent security updates for ColdFusion 2025 and ColdFusion 2023 to fix multiple vulnerabilities, including CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71386, and CVE-2026-71387. Adobe instructed administrators to upgrade to ColdFusion 2025.0.12 or 2023.0.23 and said it had not observed active exploitation in the wild.
Adobe urged ColdFusion customers to patch immediately after reports emerged that attackers were exploiting at least one maximum-severity ColdFusion vulnerability. At the time cited in the report, Adobe said it was not aware of exploits in the wild for the APSB26-68 flaws, while researchers reported targeting of CVE-2026-48282.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.