Skip to main content

Share story

Security

Adobe releases emergency ColdFusion patch APSB26-68 fixing 11 critical vulnerabilities, 6 carrying maximum CVSS 10.0 score and enabling unauthenticated remote code execution

Adobe releases emergency ColdFusion patch APSB26-68 fixing 11 critical vulnerabilities, 6 carrying maximum CVSS 10.0 score and enabling unauthenticated remote code execution Image: Primary
Adobe on June 30 released an emergency security bulletin, APSB26-68, patching 11 vulnerabilities in ColdFusion 2025 and ColdFusion 2023, six of which carry the maximum CVSS severity score of 10.0. The bulletin carries Adobe's top Priority Rating of 1, reserved for flaws that attackers are either already exploiting or are extremely likely to target soon. Adobe said it has no current evidence of in-the-wild abuse but is pressing all customers to patch without delay. The vulnerabilities enable arbitrary code execution, privilege escalation, unauthorized file system reads, and bypass of security protections. A remote attacker needing no credentials could seize full control of an exposed ColdFusion instance. Affected builds include ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier, across all supported operating systems. Fixes are in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21. The six CVSS 10.0 flaws include two unrestricted file upload bugs allowing unauthenticated attackers to drop and run malicious files on the server (CVE-2026-48276, CVE-2026-48283), three improper input validation flaws achieving the same outcome through malformed request handling (CVE-2026-48277, CVE-2026-48281, CVE-2026-48316), and a path traversal flaw leading to code execution (CVE-2026-48282).
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from CyberPress and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Infrastructure
Products Infrastructure

HPE announces $1.2 billion Vultr order and raises networking outlook

Hewlett Packard Enterprise announced a $1.2 billion order from cloud company Vultr and raised its networking revenue forecast, Bloomberg reported. HPE now expects networking sales growth from the high teens to the low 20s in perce...

Infrastructure Products
Infrastructure Products

Accelevation raises $540 million in IPO priced below marketed range

Accelevation Holdings and its private equity backer raised $540 million in an initial public offering priced below its marketed range, Bloomberg reported. Shares of the data center infrastructure company fell 2.5% after the offeri...

Capital AI
Capital AI

Flow Engineering raises $50 million at $750 million valuation

Flow Engineering raised $50 million at a $750 million valuation to help companies use AI agents to design and build hardware, Bloomberg reported. Founder and CEO Pari Singh discussed the financing on Bloomberg Tech alongside inves...

Security
Security

Cisco patches actively exploited SD-WAN authentication bypass

Cisco released fixes for CVE-2026-76504, a critical flaw in Catalyst SD-WAN Manager that the company says attackers are actively exploiting. The vulnerability lets unauthenticated attackers gain remote administrator access and aff...

Capital
Capital

Arivihan raises $10 million Series A for AI tutoring expansion

Indian education technology startup Arivihan has raised $10 million in a Series A round co-led by Accel and Prosus Ventures, the Economic Times reported. Existing GSF angel investors contributed an additional $200,000, taking tota...