Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3042 articles · 162748 vulns · 38/41 feeds (7d)
← Back to list
8.8
CVE-2026-47932EXPLOITEDPATCHED
adobe · coldfusion

ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Description

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected Products

VendorProductVersions
adobecoldfusion0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobecoldfusioncert_advisory90%

References

  • https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Adobe ColdFusion: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-47932 | Adobe ColdFusion up to 2023.19/2025.8 path traversal (apsb26-64)
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits Adobe (10 juin 2026)
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html
CWECWE-22
PublishedJun 9, 2026
Last enriched3d agov2
Trending Score40
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-47965EXP
Acrobat Reader | Out-of-bounds Write (CWE-787)
Trending: 50
HIGHCVE-2026-47911EXP
Acrobat Reader | Out-of-bounds Write (CWE-787)
Trending: 40
HIGHCVE-2026-47955EXP
Acrobat Reader | Use After Free (CWE-416)
Trending: 40
HIGHCVE-2026-47959EXP
Acrobat Reader | Stack-based Buffer Overflow (CWE-121)
Trending: 40
HIGHCVE-2026-47931EXP
ColdFusion | Improper Input Validation (CWE-20)
Trending: 40

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: severity, activelyExploited
Jun 10, 2026
Actively Exploited
Jun 11, 2026
Patch Available
Jun 11, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit is available.

severityactivelyExploited
via VulDB
v13d ago

Initial creation