Lead CVECVE-2026-48362
CVSS 10.0
Also patchedCVE-2026-48273
CVSS 9.9 (eval inj)
CVE-2026-71384
CVSS 9.6 (auth bypass)
Fixed inCF 2025: 2025.0.12
CF 2023: 2023.0.23
PriorityAdobe Priority 1
(patch within 72h)
ExploitationNot confirmed
in wild yet
What happened
Adobe published security bulletin APSB26-83 on August 12, 2026, addressing multiple critical vulnerabilities in Adobe ColdFusion 2025 and ColdFusion 2023. The most severe flaw is CVE-2026-48362, an OS command injection vulnerability rated CVSS 10.0. The vulnerability arises from improper neutralization of special elements used in operating system commands, allowing an unauthenticated remote attacker to execute arbitrary commands in the context of the ColdFusion service account. On Windows, that account is typically NT AUTHORITY\SYSTEM, the highest level of access on the operating system. No authentication and no user interaction are required. The same bulletin addresses CVE-2026-48273, a CVSS 9.9 eval injection vulnerability that can lead to arbitrary code execution by an attacker with low-level privileges, and CVE-2026-71384, a CVSS 9.6 incorrect authorization vulnerability that can produce application denial-of-service. Adobe also addressed CVE-2026-71362, a CVSS 9.1 incorrect authorization flaw in Adobe Commerce that can lead to privilege escalation, and CVE-2026-48381, a CVSS 9.0 SQL injection in Adobe Campaign Classic that can lead to code execution. Fixed ColdFusion versions are 2025.0.12 and 2023.0.23. Adobe assigned its Priority 1 rating to the ColdFusion and Campaign Classic updates, which Adobe describes as a recommendation to install within 72 hours due to elevated risk of being targeted by malicious attacks. Adobe stated it is not aware of any exploits targeting these vulnerabilities in the wild as of the publication date.
Why it matters
Adobe ColdFusion has an active exploitation pattern that makes the absence of confirmed in-the-wild exploitation at publication time a limited reassurance. CVE-2026-48282, a separate ColdFusion path traversal flaw patched in June, was being exploited within days of its disclosure. KEVIntel honeypots detected active exploitation of that flaw within two hours of the technical write-up. ColdFusion is used in government agencies, healthcare systems, financial institutions, and enterprise web applications. An OS command injection on a ColdFusion server typically gives an attacker the ability to install a webshell, exfiltrate data, pivot to connected databases, and move laterally through the host's network. The CVSS 10.0 rating and Priority 1 designation reflect the maximum practical impact of the flaw: unauthenticated, no user interaction, arbitrary OS command execution as SYSTEM.
Don't miss
The ColdFusion advisory is the third major Adobe security release this month, alongside the emergency SAP CVE-2026-58231 note from Issue 107 and the vCenter campaign from Issue 107. Organizations managing enterprise web application infrastructure are navigating simultaneous critical patches from Adobe, SAP, Microsoft, Cisco, and VMware in the same week. Adobe's 72-hour Priority 1 guidance for ColdFusion is the correct prioritization signal. The broader enterprise patching queue this week, including today's Cisco ASA deadline, last week's Metabase zero-day, and the ongoing vCenter campaign, reflects the sustained high-volume patching environment this brief documented across all of July and August. Triage by exploitation status and internet exposure remains the only workable framework: ColdFusion CVE-2026-48362 is not yet exploited but has a recent predecessor that was. The Cisco CVE is already being exploited. The GeoServer zero-day has no patch at all. Those three categories require different response timelines even when they arrive on the same day.
Potential actions
- Update ColdFusion 2025 deployments to version 2025.0.12 and ColdFusion 2023 deployments to version 2023.0.23 within 72 hours per Adobe's Priority 1 guidance. Internet-facing ColdFusion servers are the highest-priority update targets given the unauthenticated attack surface of CVE-2026-48362.
- Also apply the Campaign Classic update for CVE-2026-48381 and the Commerce update for CVE-2026-71362 if those products are in use. Adobe-hosted instances of Campaign Classic have already been remediated and require no action. On-premise deployments and hybrid on-premise components require manual update.
The Sip
No authentication. No interaction. OS commands execute as SYSTEM. Not exploited in the wild yet, but last month's ColdFusion advisory was actively attacked within hours of the technical write-up. Adobe says patch within 72 hours. The clock started August 12.