CVE-2026-48281

CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploita...

Affects 0 products across 1 vendor.

CVSS 3.110.0
EPSS1.8%
Percentile77th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical severity vulnerability (CVE-2026-48281) affects the target system. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-48281?
A critical severity vulnerability (CVE-2026-48281) affects the target system. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction....
What is the CVSS score for CVE-2026-48281?
CVE-2026-48281 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 1.8%.
Is CVE-2026-48281 actively exploited?
No confirmed active exploitation of CVE-2026-48281 as of 2026-07-01.
How do I remediate CVE-2026-48281?
Apply vendor patches for CVE-2026-48281. Monitor Adobe advisories.
What systems are affected by CVE-2026-48281?
CVE-2026-48281 affects: Adobe.
Vulnerability Details
CVE IDCVE-2026-48281
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-06-30
Last Modified2026-06-30
Weakness (CWE)
SourceNVD
Official Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Adobe —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 32 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Adobe
CVE-2009-3959 10.0 Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x be... CVE-2015-5101 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 ... CVE-2015-6691 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 ... CVE-2004-0631 10.0 Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and ... CVE-2004-1152 10.0 Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 fo...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →