NCSC-2026-0217 [1.00] [M/H] Vulnerabilities fixed in Adobe ColdFusion
Adobe has fixed multiple vulnerabilities in Adobe ColdFusion versions 25.9, 23.20, and earlier versions. The vulnerabilities in Adobe ColdFusion include unrestricted upload of dangerous file types, improper input validation, path traversal, reflected Cross-Site Scripting (XSS), and Server-Side Request Forgery (SSRF). These vulnerabilities allow an attacker to execute arbitrary code without any user interaction, read or write files, and bypass security measures. The path traversal vulnerabilities can lead to access to and modification of files outside the intended directories. The XSS vulnerability arises from insufficient sanitization of user input in URLs, allowing malicious scripts to be injected and executed in a user's browser. The SSRF vulnerability allows an attacker to manipulate server-side requests and gain unauthorized access to resources. These issues are present in multiple versions of ColdFusion, indicating a broad impact area within the product line.
CSIRTS triage
- What
- Multiple vulnerabilities in Adobe ColdFusion allow for arbitrary code execution, file access, and security bypass.
- Who is affected
- Deployments of Adobe ColdFusion versions 25.9, 23.20, and earlier are affected.
- Urgency
- Remediation is urgent due to the high severity of the vulnerabilities and potential exploitation.
- Action
- Upgrade to the latest version of Adobe ColdFusion to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ColdFusion
Get an email when a new ColdFusion advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0217
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-482765.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482771.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482812.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-48282Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482831.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483134.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483151.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 71% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483070.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-482850.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-483140.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48276 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48277 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48281 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48282 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48283 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48316 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[UPDATE] [critical] Adobe ColdFusion: Multiple Vulnerabilitiescert-bund
- criticalexploitedAdobe security advisory (AV26-647) – Update 2cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerabilitycisa-kev
- criticalCVE-2026-48316: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation v…nvd
- unknownMultiple vulnerabilities in Adobe ColdFusion (July 1, 2026)cert-fr-avis
- criticalCVE-2026-48315: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation v…nvd
- mediumCVE-2026-48314: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pa…nvd
- criticalCVE-2026-48313: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pa…nvd
- highCVE-2026-48307: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripti…nvd
- highCVE-2026-48285: ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery …nvd
- criticalCVE-2026-48283: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21