CVE-2026-48276: critical vulnerability (CVSS 10.0)
CVE-2026-48276 affects ColdFusion versions 2025.9, 2023.20, and earlier, enabling arbitrary code execution via unrestricted file uploads. No user interaction is required, and the vulnerability carries a CVSS score of 10.0 due to its critical impact and scope change.
Prioritize patching ColdFusion instances immediately and review upload handling mechanisms. Consider implementing stricter file type validation and monitoring for suspicious activity in affected environments.
ColdFusion versions 2025.9, 2023.20, and earlier have a critical flaw (CVE-2026-48276) allowing attackers to upload and execute malicious files without user interaction. The vulnerability enables arbitrary code execution under the current user’s permissions.
The CVSS score of 10.0 reflects the high impact and ease of exploitation, compounded by a scope change that broadens the attack vector. Systems running affected versions are at heightened risk of compromise.
Administrators should immediately apply vendor-issued patches or mitigations, disable unnecessary file upload functionality, and monitor for indicators of compromise. Enhanced input validation and logging are recommended to reduce exposure.