CVE-2026-48273
Ein Angreifer kann mehrere Schwachstellen in Adobe ColdFusion ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Adobe ColdFusion enable remote code execution, privilege escalation, denial of service, information disclosure, cross-site scripting, and authentication bypass.
- Who is affected
- Organizations running Adobe ColdFusion servers exposed to network threats.
- Urgency
- High severity with critical RCE impact and multiple attack vectors; update immediately.
- Action
- Update Adobe ColdFusion to the latest security release addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-48273
Get an email if CVE-2026-48273 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk1.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
Advisory coverage (6)
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- high[UPDATE] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownMultiples vulnérabilités dans les produits Adobe (09 septembre 2026)cert-fr-avis · 2026-09-09
- criticalCVE-2026-48273: ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Co…nvd · 2026-09-08
- unknownMultiple vulnerabilities in Adobe products (August 13, 2026)cert-fr-avis · 2026-08-13
- unknownNCSC-2026-0294 [1.00] [M/H] Vulnerabilities patched in Adobe ColdFusionncsc-nl · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-48273)