.

Adobe Security Bulletin

Last updated on Sep 3, 2026

Security updates available for Adobe ColdFusion | APSB26-90

Bulletin ID
Date published
Priority
APSB26-90
August 11, 2026
1

Summary

Adobe has released a security update for ColdFusion versions 2025 and 2023. This update resolves critical and important vulnerabilities that could result in arbitrary code execution, privilege escalation, security feature bypass, application denial-of-service, and memory exposure.

Adobe is not aware of any exploits in the wild for any of the issues addressed in this update.

Affected Versions

Product
Update number
Platform
ColdFusion 2025
2025.0.11 and earlier versions
All
ColdFusion 2023
2023.0.22 and earlier versions
All

Solution

Adobe categorizes these updates with the following priority rating and recommends users update their installations to the newest versions:

Product
Updated version
Platform
Priority rating
Availability
ColdFusion 2025
2025.0.12
All
1
ColdFusion 2023
2023.0.23
All
1

Vulnerability Details

Vulnerability category
Vulnerability impact
Severity
CVSS base score
CVSS vector
CVE number
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Arbitrary code execution
Critical
10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48362
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Arbitrary code execution
Critical
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-48273
Incorrect Authorization (CWE-863)
Application denial-of-service
Critical
9.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-71384
Cross-site Scripting (XSS) (CWE-79)
Arbitrary code execution
Critical
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-71386
Improper Input Validation (CWE-20)
Privilege escalation
Critical
8.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVE-2026-21273
Incorrect Authorization (CWE-863)
Arbitrary code execution
Critical
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-71387
Incorrect Authorization (CWE-863)
Security feature bypass
Critical
8.4
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVE-2026-71385
Use of Hard-coded Cryptographic Key (CWE-321)
Security feature bypass
Critical
8.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE-2026-34635
Heap-based Buffer Overflow (CWE-122)
Arbitrary code execution
Critical
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-48440
Improper Input Validation (CWE-20)
Security feature bypass
Critical
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVE-2026-21279
Incorrect Authorization (CWE-863)
Privilege escalation
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-25652
Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Memory exposure
Critical
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2026-48386
Incorrect Authorization (CWE-863)
Security feature bypass
Important
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE-2026-71383
Improper Authentication (CWE-287)
Privilege escalation
Important
7.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CVE-2026-83961
Incorrect Authorization (CWE-863)
Application denial-of-service
Important
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48375
Improper Encoding or Escaping of Output (CWE-116)
Security feature bypass
Important
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVE-2026-48376
Improper Input Validation (CWE-20)
Security feature bypass
Important
4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVE-2026-48384

Acknowledgements:

AnirudhAnand (a0xnirudh) — CVE-2026-71386