Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3041 articles · 162749 vulns · 38/41 feeds (7d)
← Back to list
8.4
CVE-2026-47931EXPLOITEDPATCHED
adobe · coldfusion

ColdFusion | Improper Input Validation (CWE-20)

Description

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobecoldfusion0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobecoldfusioncert_advisory90%

References

  • https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Adobe ColdFusion: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-47931 | Adobe ColdFusion up to 2023.19/2025.8 input validation (apsb26-64)
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits Adobe (10 juin 2026)
→ No new info (linked only)
CVSS 3.18.4 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html
CWECWE-20
PublishedJun 9, 2026
Last enriched3d agov2
Trending Score40
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-47965EXP
Acrobat Reader | Out-of-bounds Write (CWE-787)
Trending: 49
HIGHCVE-2026-47911EXP
Acrobat Reader | Out-of-bounds Write (CWE-787)
Trending: 40
HIGHCVE-2026-47955EXP
Acrobat Reader | Use After Free (CWE-416)
Trending: 40
HIGHCVE-2026-47959EXP
Acrobat Reader | Stack-based Buffer Overflow (CWE-121)
Trending: 40
HIGHCVE-2026-47932EXP
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 40

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, affectedVersions, activelyExploited
Jun 10, 2026
Actively Exploited
Jun 11, 2026
Patch Available
Jun 11, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated affected versions to include 2023.19 and 2025.8, marked exploit as unavailable, and noted that the vulnerability is actively exploited.

descriptionaffectedVersionsactivelyExploited
via VulDB
v13d ago

Initial creation