LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-48322

adobe · coldfusion

Published
CVSS9.9
Severitycritical
WeaknessCWE-94
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-48322

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-48322.