Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2026-27304
Critical
Low
Medium
High
Critical
9.3
CVSS Score
Vulnerability Description
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
A
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
C
Confidentiality
H
Integrity
H
Availability
N
Known Affected Software
2 configuration(s) from 1 vendor(s)
coldfusion
Version:
2025
CPE:
cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*
coldfusion
Version:
2023
CPE:
cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*
This vulnerability affects 2 software configuration(s). Ensure you patch all affected systems.
Severity Details
9.3
out of 10.0
Critical
Weakness Type (CWE)
CWE-20
Top 25 #14
Improper Input Validation
- Description
- The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Class
Key Information
- Published Date
- April 14, 2026
