.

Adobe Security Bulletin

Last updated on Jul 14, 2026

Security updates available for Adobe ColdFusion | APSB26-82

Bulletin ID
Date published
Priority
APSB26-82
July 14, 2026
1

Summary

Adobe has released security updates for ColdFusion versions 2025 and 2023. These updates resolve critical, important, and moderate vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates.

Affected Versions

Product
Update number
Platform
ColdFusion 2025
Update 10 and earlier versions
All
ColdFusion 2023
Update 21 and earlier versions
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installations to the newest versions:

Product
Updated version
Platform
Priority rating
Availability
ColdFusion 2025
Update 11
All
1
ColdFusion 2023
Update 22
All
1

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary code execution
Critical
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48318
Improper Control of Generation of Code ('Code Injection') (CWE-94)
Arbitrary code execution
Critical
9.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE-2026-48322
Improper Input Validation (CWE-20)
Arbitrary code execution
Critical
9.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48284
Incorrect Authorization (CWE-863)
Privilege escalation
Critical
9.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVE-2026-48321
Missing Authentication for Critical Function (CWE-306)
Arbitrary code execution
Critical
9.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVE-2026-48325
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary code execution
Critical
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48319
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Arbitrary code execution
Critical
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48324
Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical
9.0
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48327
Cross-site Scripting (Reflected XSS) (CWE-79)
Privilege escalation
Critical
8.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-48320
Improper Input Validation (CWE-20)
Security feature bypass
Critical
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48328
Server-Side Request Forgery (SSRF) (CWE-918)
Security feature bypass
Critical
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48332
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Arbitrary file system read
Critical
6.8
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48338
Insufficient Session Expiration (CWE-613)
Security feature bypass
Moderate
2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVE-2026-48329

Acknowledgements:

Adobe would like to thank the following researchers for reporting this issue and for working with Adobe to help protect our customers:

  • Matan Sandori (matans1) and 2Bsecure - CVE-2026-48320
  • Tahmid Akbar Omim (imperial_coder) - CVE-2026-48327
  • Rajin Hasnine (retro__) - CVE-2026-48329