NCSC-2026-0294 [1.00] [M/H] Vulnerabilities patched in Adobe ColdFusion
Adobe has patched multiple vulnerabilities in Adobe ColdFusion versions 2025.0.11, 2023.0.22 and earlier versions. The vulnerabilities in Adobe ColdFusion can be exploited by unauthenticated malicious actors to execute arbitrary code remotely, bypass security measures, escalate privileges on the system or disrupt the operation of the application through DoS.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthenticated remote code execution, security bypass, privilege escalation, and denial of service.
- Who is affected
- Adobe ColdFusion 2025.0.11, 2023.0.22 and earlier versions.
- Urgency
- Critical; unauthenticated remote code execution poses extreme risk and requires immediate patching.
- Action
- Update ColdFusion to patched versions newer than 2025.0.11 and 2023.0.22.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ColdFusion
Get an email when a new ColdFusion advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0294
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-713840.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483624.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-482731.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-713866.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-713870.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-346350.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484400.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-212790.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256520.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71384 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48362 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48273 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71385 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34635 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48440 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-21279 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48375 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48376 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48384 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl
- high[UPDATE] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits Adobe (09 septembre 2026)cert-fr-avis
- criticalCVE-2026-48273: ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Co…nvd
- unknownMultiple vulnerabilities in Adobe products (August 13, 2026)cert-fr-avis
- highCVE-2026-71387: ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitr…nvd
- highCVE-2026-71386: is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code …nvd
- criticalCVE-2026-71384: is affected by an Incorrect Authorization vulnerability that could result in a Security featur…nvd
- highCVE-2026-71383: is affected by an Incorrect Authorization vulnerability that could result in a Security featur…nvd
- highCVE-2026-48440: ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbi…nvd
- highCVE-2026-48386: ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability tha…nvd
- mediumCVE-2026-48384: ColdFusion is affected by an Improper Input Validation vulnerability that could result in an a…nvd
Recent advisories for Adobe ColdFusion
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- high[NEU] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund · 2026-09-09
- high[UPDATE] [hoch] Adobe ColdFusion: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownNCSC-2026-0241 [1.00] [M/H] Vulnerabilities fixed in Adobe ColdFusionncsc-nl · 2026-07-16
- high[NEW] [high] Adobe ColdFusion: Multiple vulnerabilitiescert-bund · 2026-07-15
- critical[UPDATE] [critical] Adobe ColdFusion: Multiple Vulnerabilitiescert-bund · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able2026-09-11