FORSMILE
JA
セキュリティ2026/06/30

[URGENT] Adobe ColdFusion CVE-2026-48276: Update to 2025 Update 10 or 2023 Update 21

An unrestricted upload of a dangerous file type can lead to code execution without authentication or user interaction. Install the fixed releases in Adobe bulletin APSB26-68.

← Back to Blog

Adobe ColdFusion is affected by CVE-2026-48276, an unrestricted upload of a dangerous file type that can lead to arbitrary code execution in the context of the ColdFusion service user. Exploitation requires neither authentication nor user interaction. Adobe's CNA assessment is CVSS v3.1 10.0 CRITICAL.

Vulnerability Overview and Scope of Impact

ColdFusion 2025 Update 9 and earlier and ColdFusion 2023 Update 20 and earlier are affected. Fixed releases are ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. Execution occurs in the current service user's context and must not automatically be described as root or SYSTEM.

⚠ CVE Score — 最高危険度 / CRITICAL
10CRITICALCVSS v3.1CVE-2026-48276

Note: A CVSS score of 9.8 is an estimated value based on the nature of the vulnerability, which allows arbitrary code execution. Detailed score calculation by NVD may still be in progress. Similar RCE vulnerabilities in ColdFusion have been rated with CVSS scores of 9.1 and 9.6.

Specific Impacts and Attack Scenarios

Attackers can exploit this vulnerability to upload malicious files, such as web shells, to servers running ColdFusion applications. This could lead to the following attack scenarios:

1. Full System Control (RCE): Through the uploaded malicious script, attackers can execute arbitrary OS commands on the server, including viewing, editing, deleting files in the file system, and installing new malware, thereby gaining full control over the system.

2. Information Leakage: Database connection details (e.g., configuration files like wp-config.php), customer information, and other sensitive files could be stolen.

3. Website Defacement / Stepping Stone: Website content could be defaced, or the server could be exploited as a relay (stepping stone) for DDoS attacks or spam email distribution.

Actions Engineers Should Take Immediately

Follow Adobe APSB26-68 and update the 2025 branch to Update 10 or later and the 2023 branch to Update 21 or later. Verify the installed update level, inspect public and temporary directories for unexpected files, and review ColdFusion and web-server logs. APSB26-68 is the official bulletin for this CVE.

📦
Search Amazon US for related books and tools
cybersecurity server security tools
Search Amazon US → (affiliate link). As an Amazon Associate, we earn from qualifying purchases.

References and Official Patch Information

Related articles