Crypto Ticker:
sysadmin from Cyber Security News

Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code

Guru Baran
13 hours ago
8 Views
0 Comments
Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code

Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability. Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent. Adobe ColdFusion Flaws Enable Code Execution The most alarming flaw resolved in this batch is CVE-2026-48362, an unauthenticated OS command injection vulnerability with a maximum CVSS base score of 10.0. The flaw allows remote, unauthenticated attackers to execute arbitrary operating system commands on vulnerable ColdFusion servers...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!