What is CVE-2026-48362?
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
- 2026-08-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-13First covered in a defend.network daily briefing
- 2026-08-28NVD record last updated
Affected product
Adobe Coldfusion
Remediation Steps
- Apply Adobe security update for ColdFusion OS command injection
- Review and update ColdFusion instances to patched versions
- Audit system command execution logs for suspicious activity
- Restrict ColdFusion application permissions to minimum required
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.