CVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Description
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
In plain language
AI Act nowCVE-2026-48362 is a serious ColdFusion flaw that lets an attacker send specially crafted network requests and run commands on your server with no login needed—if you use ColdFusion 2023 or 2025 and haven’t installed the fixed update, you should act.
ColdFusion suffers from OS Command Injection (CWE-78) allowing unauthenticated, network-triggered command execution in the context of the ColdFusion service account, with no user interaction required.
What to do now
- Check which ColdFusion version you run (ColdFusion 2023 or ColdFusion 2025) and whether it is updated past 2025.0.12 and 2023.0.23.
- If you are on ColdFusion 2025, upgrade ColdFusion to 2025.0.12 or later.
- If you are on ColdFusion 2023, upgrade ColdFusion to 2023.0.23 or later.
- After upgrading, verify the service is running the updated build and review logs for suspicious command-like activity around the time of any probing.
- If you cannot patch right away, restrict network access to the ColdFusion admin and application endpoints so the service is not reachable from the public internet.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and Moreen·The Hacker News· Exploited Lazarus Group ransomware
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flawsen·The Hacker News· Patch ColdFusion web-app
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flawsen-us·SecurityWeek· Patch ColdFusion rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48362 and every CVE in our database. Create a free account — no credit card required.
Create Free Account