Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code

Adobe has issued critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing multiple vulnerabilities that could allow threat actors to execute arbitrary code, bypass security controls, escalate privileges, expose sensitive memory, or disrupt application availability. Given the potential impact across enterprise web infrastructure, Adobe has designated this update cycle as urgent. Adobe ColdFusion Flaws Enable Code Execution The most alarming flaw resolved in this batch is CVE-2026-48362, an unauthenticated OS command injection vulnerability with a maximum CVSS base score of 10.0. The flaw allows remote, unauthenticated attackers to execute arbitrary operating system commands on vulnerable ColdFusion servers without any user interaction. On internet-exposed servers, this grants attackers an immediate path to full host takeover.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could

·The Hacker News
Read →

You've reached the end of current stories for this search.