Ce mail provient de l'extérieur, restons vigilants

====================================================================
                            CERT-Renater

                Note d'Information No. 2026/VULN708
_____________________________________________________________________

DATE                : 01/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Adobe ColdFusion versions prior
                           to 2025 Update 10, 2023 Update 21.
 
====================================================================
https://helpx.adobe.com/uk/security/products/coldfusion/apsb26-68.html
_____________________________________________________________________


Security update available for Adobe ColdFusion | APSB26-68

Bulletin ID     Date Published         Priority

APSB26-68       June 30, 2026          1


Summary

Adobe has released security updates for ColdFusion versions 2025 and 2023.
These updates resolves critical and important vulnerabilities that could
lead to arbitrary code execution, privilege escalation, arbitrary file
system read, and security feature bypass.

 Adobe is not aware of any exploits in the wild for any of the issues
addressed in these updates.


Affected Versions

Product              Update number                  Platform

ColdFusion 2025      Update 9 and earlier versions   All

ColdFusion 2023      Update 20 and earlier versions  All


Solution

Adobe categorizes these updates with the following priority rating
and recommends users update their installations to the newest
versions:

Product   Updated Version   Platform   Priority rating   Availability

ColdFusion 2025   Update 10   All      1               Tech Note

ColdFusion 2023   Update 21   All      1               Tech Note

Note

For security reasons, we strongly recommend to use latest mysql java
connector. For more information on its usage, please  refer to:
https://helpx.adobe.com/coldfusion/kb/coldfusion-configuring-mysql-jdbc.html

 See the updated serial filter documentation for more details on
protection against insecure deserialization attacks:
https://helpx.adobe.com/coldfusion/kb/coldfusion-serialfilter-file.html


Vulnerability Details

Vulnerability Category         Vulnerability Impact         Severity
CVSS base score         CVSS vector         CVE Number

Unrestricted Upload of File with Dangerous Type (CWE-434)
Arbitrary code execution         Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H         CVE-2026-48276

Improper Input Validation (CWE-20)         Arbitrary code execution
Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H         CVE-2026-48277

Improper Input Validation (CWE-20)         Arbitrary code execution
Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H         CVE-2026-48281

Improper Input Validation (CWE-20)         Arbitrary code execution
Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N         CVE-2026-48316

Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)         Arbitrary code execution
Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H         CVE-2026-48282

Unrestricted Upload of File with Dangerous Type (CWE-434)
Arbitrary code execution         Critical         10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H         CVE-2026-48283

Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)         Arbitrary file system read
Critical         9.3         CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVE-2026-48313

Improper Input Validation (CWE-20)         Privilege escalation
Critical         9.3         CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-48315

Cross-site Scripting (Reflected XSS) (CWE-79)         Arbitrary code execution
Critical         8.8         CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-48307
Server-Side Request Forgery (SSRF) (CWE-918)         Security feature bypass
Critical         8.6         CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE-2026-48285

Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)         Privilege escalation         Important
6.5         CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N         CVE-2026-48314


Acknowledgements:

Adobe would like to thank the following researchers for reporting this
issue and for working with Adobe to help protect our customers:   

    AnirudhAnand (a0xnirudh) - CVE-2026-48283, CVE-2026-48313
    Matan Sandori (matans1) and 2Bsecure - CVE-2026-48307

NOTE: Adobe has a public bug bounty program with HackerOne. If you
are interested in working with Adobe as an external security researcher,
please check out https://hackerone.com/adobe

Note

Adobe recommends updating your ColdFusion JDK/JRE LTS version to the
latest update release as a secure practice. The ColdFusion downloads
page is regularly updated to include the latest Java installers for
the JDK version your installation supports as per the matrices below.

    ColdFusion 2025 support matrix
    ColdFusion 2023 support matrix

For instructions on how to use an external JDK, view Change ColdFusion JVM.

Adobe also recommends applying the security configuration settings
included in the ColdFusion Security documentation as well as review
the respective Lockdown guides.   

    ColdFusion 2025 Lockdown Guide
    ColdFusion 2023 Lockdown Guide


========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +

========================================================



