NCSC-2026-0294 [1.00] [M/H] Vulnerabilities patched in Adobe ColdFusion
Adobe has patched multiple vulnerabilities in Adobe ColdFusion versions 2025.0.11, 2023.0.22 and earlier versions. The vulnerabilities in Adobe ColdFusion can be exploited by unauthenticated malicious actors to execute arbitrary code remotely, bypass security measures, escalate privileges on the system or disrupt the operation of the application through DoS.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthenticated remote code execution, security bypass, privilege escalation, and denial of service.
- Who is affected
- Adobe ColdFusion 2025.0.11, 2023.0.22 and earlier versions.
- Urgency
- Critical; unauthenticated remote code execution poses extreme risk and requires immediate patching.
- Action
- Update ColdFusion to patched versions newer than 2025.0.11 and 2023.0.22.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ColdFusion
Get an email when a new ColdFusion advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0294
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-713840.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-483622.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-713860.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-713870.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-346350.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484400.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-212790.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-256520.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71384 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48362 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48273 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71385 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34635 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48440 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-21279 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48386 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48375 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48376 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48384 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Adobe products (August 13, 2026)cert-fr-avis
- high[NEW] [high] Adobe ColdFusion: Multiple Vulnerabilitiescert-bund
- highCVE-2026-71387: ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitr…nvd
- highCVE-2026-71386: is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code …nvd
- criticalCVE-2026-71384: is affected by an Incorrect Authorization vulnerability that could result in a Security featur…nvd
- highCVE-2026-71383: is affected by an Incorrect Authorization vulnerability that could result in a Security featur…nvd
- highCVE-2026-48440: ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbi…nvd
- highCVE-2026-48386: ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability tha…nvd
- mediumCVE-2026-48384: ColdFusion is affected by an Improper Input Validation vulnerability that could result in an a…nvd
- mediumCVE-2026-48376: is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a…nvd
- mediumCVE-2026-48375: ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an app…nvd
- criticalCVE-2026-48362: ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21