Unauthenticated OS Command Injection RCE in Adobe ColdFusion
CVSS 3.1
10.0critical
EPSS
4%p91
Published
()
Modified
AI analysis
Adobe ColdFusion is affected by an OS command injection vulnerability (CWE-78, Improper Neutralization of Special Elements used in an OS Command) rated critical at CVSS 10.0. It is triggered over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N), so any network-accessible ColdFusion server is directly reachable by an unauthenticated attacker. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed scope (S:C) indicates the injected commands can impact resources beyond the vulnerable ColdFusion component itself, such as other services or systems reachable from it. All ColdFusion deployments are plausibly affected; the data does not specify affected or fixed version ranges, so administrators should check Adobe's security bulletin (the related coverage notes Adobe patched this flaw alongside Campaign Classic issues). Exploitation has not been confirmed: it is not in CISA KEV and no public proof-of-concept is known, though EPSS assigns a 4.3% probability of exploitation within 30 days (91st percentile), warranting prompt patching.
What to do: Apply the ColdFusion security update published in Adobe's security bulletin as the primary fix, prioritizing internet-facing ColdFusion servers because the vector is network-based and unauthenticated; check the bulletin for exact affected and fixed version numbers, which were not included in this data. As interim mitigation, restrict network access to ColdFusion services and review web and access logs for signs of command-execution or probing activity given the elevated EPSS score.
Affected
Adobe ColdFusion
—
Estimated exposure
largetens of thousands of installations, with only a few thousand likely internet-exposed — Adobe does not publish active-install counts for ColdFusion, but public internet scans typically show only a few thousand exposed ColdFusion servers, implying a broader total installed base in the tens of thousands, many of which sit…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.
Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.