CVE-2026-47928: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict the vulnerable ColdFusion component to the administrative network zone (it is restricted by default) to reduce exposure.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47928?
CVE-2026-47928 has a critical severity rating of 9.6.
How do I fix CVE-2026-47928?
To mitigate CVE-2026-47928, update to Adobe ColdFusion version 2023.20, 2025.9, or later.
What types of attacks can CVE-2026-47928 facilitate?
CVE-2026-47928 can facilitate arbitrary code execution in the context of the current user.
Does exploitation of CVE-2026-47928 require user interaction?
No, exploitation of CVE-2026-47928 does not require user interaction.
Which versions of ColdFusion are affected by CVE-2026-47928?
CVE-2026-47928 affects Adobe ColdFusion versions 2023.19, 2025.8, and earlier.