What is CVE-2026-48362?
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
- 2026-08-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-12NVD record last updated
- 2026-08-13First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Apply Adobe security update for ColdFusion and Campaign Classic
- Disable or restrict access to affected ColdFusion services until patches are deployed
- Review access logs for evidence of command injection attempts
- Implement input validation and command-line argument sanitization
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.