.

Adobe Security Bulletin

Last updated on Sep 8, 2026

Security updates available for Adobe ColdFusion | APSB26-119

Bulletin ID
Date published
Priority
APSB26-119
September 8, 2026
1

Summary

Adobe has released a security update for ColdFusion versions 2025 and 2023. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, privilege escalation, arbitrary file system read, and application denial-of-service.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Affected Versions

Product
Update number
Platform
ColdFusion 2025
2025.0.12 and earlier versions
All
ColdFusion 2023
2023.0.23 and earlier versions
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installations to the newest versions:

Product
Updated version
Platform
Priority rating
Availability
ColdFusion 2025
2025.0.13
All
1
ColdFusion 2023
2023.0.24
All
1

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Arbitrary code execution
Critical
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48273
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Arbitrary code execution
Critical
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVE-2026-75746
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Arbitrary code execution
Critical
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVE-2026-76190
Cross-site Scripting (Reflected XSS) (CWE-79)
Privilege escalation
Critical
8.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-75993
Improper Input Validation (CWE-20)
Arbitrary code execution
Critical
8.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-75999
Improper Access Control (CWE-284)
Arbitrary file system read
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2026-75998
Uncontrolled Resource Consumption (CWE-400)
Application denial-of-service
Important
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-76000
Cross-site Scripting (Reflected XSS) (CWE-79)
Arbitrary code execution
Important
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE-2026-76002
Cross-site Scripting (Stored XSS) (CWE-79)
Arbitrary code execution
Important
4.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVE-2026-21269

Acknowledgements:

COLDFUSION 2025 (version 2023.0.0.331385) and above
For Application Servers

On JEE installations, set the following JVM flag, “-Djdk.serialFilter= !org.mozilla.**;!com.sun.syndication.**;!org.apache.commons.beanutils.**;!org.jgroups.**;!com.sun.rowset.**; !com.mysql.cj.jdbc.interceptors.**;!org.apache.commons.collections.**; " in the respective startup file depending on the type of Application Server being used.

  • AnirudhAnand (a0xnirudh) — CVE-2026-48273
  • wayne g (waynezinn) — CVE-2026-75746, CVE-2026-75998
  • anonymous_blackzero — CVE-2026-75993
  • Matan Sandori (matans1) — CVE-2026-75999, CVE-2026-76000, CVE-2026-76002