Adobe ColdFusion Improper Input Validation Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. This issue arises from improper input validation and can be exploited without user interaction, executing the malicious code in the context of the current user.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Remediation

Users are advised to update to ColdFusion 2025 Update 7 or ColdFusion 2023 Update 19. For more information, refer to the Adobe ColdFusion 2025 Update 7 Tech Note or the Adobe ColdFusion 2023 Update 19 Tech Note.

Added: Apr 15, 2026, 12:50 AM
Updated: Apr 15, 2026, 12:50 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
7.5
exploitability
5.4
remediation
7.7
relevance
5.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.