Multiple vulnerabilities have been discovered in Adobe ColdFusion software, allowing attackers to execute remote code, elevate privileges, and compromise data confidentiality. The CERT‑FR alert cites seven CVEs (CVE‑2026‑48276 to CVE‑2026‑48316) that affect ColdFusion 2023 versions prior to Update 21 and ColdFusion 2025 versions prior to Update 10. Reported risks include remote arbitrary code execution, remote privilege escalation, data confidentiality breaches, server‑side request forgery, indirect remote code injection (XSS), and server‑side request forgery. Users are advised to consult Adobe’s security bulletin APSB26‑68 for patches and apply the latest updates as soon as they become available. The alert was issued on 1 July 2026 by the French national information security agency.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.