.

Adobe Security Bulletin

Last updated on Jul 13, 2026

Security update available for Adobe ColdFusion | APSB26-68

Bulletin ID
Date published
Priority
APSB26-68
June 30, 2026
1

Summary

Adobe has released security updates for ColdFusion versions 2025 and 2023. These updates resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe is aware that CVE-2026-48282 has been exploited in the wild in limited attacks targeting Adobe ColdFusion.

Affected Versions

Product
Update number
Platform
ColdFusion 2025
Update 9 and earlier versions
All
ColdFusion 2023
Update 20 and earlier versions
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installations to the newest versions:

Product
Updated version
Platform
Priority rating
Availability
ColdFusion 2025
Update 10
All
1
ColdFusion 2023
Update 21
All
1

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Unrestricted Upload of File with Dangerous Type (CWE-434)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48276
Improper Input Validation (CWE-20)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48277
Improper Input Validation (CWE-20)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48281
Improper Input Validation (CWE-20)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVE-2026-48316
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48282
Unrestricted Upload of File with Dangerous Type (CWE-434)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48283
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary file system read
Critical
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVE-2026-48313
Improper Input Validation (CWE-20)
Privilege escalation
Critical
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-48315
Cross-site Scripting (Reflected XSS) (CWE-79)
Arbitrary code execution
Critical
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48307
Server-Side Request Forgery (SSRF) (CWE-918)
Security feature bypass
Critical
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48285
Uncontrolled Search Path Element (CWE-427)
Privilege escalation
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48363
Uncontrolled Search Path Element (CWE-427)
Privilege escalation
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48364
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Privilege escalation
Important
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVE-2026-48314

Acknowledgements:

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers:

  • AnirudhAnand (a0xnirudh) - CVE-2026-48283, CVE-2026-48313
  • Matan Sandori (matans1) and 2Bsecure - CVE-2026-48307
  • gee-netics - CVE-2026-48363
  • sneharghyaroy - CVE-2026-48364