BlackTreeCVE IntelligenceOfficial source evidenceAdobeAPSB26-68
Official source article · Adobe
Security update available for Adobe ColdFusion | APSB26-68
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗PublisherAdobe
Article IDAPSB26-68
Verified snapshot27 Sept 2026, 14:00 UTC
Linked CVEs13
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-48315ColdFusion | Improper Input Validation (CWE-20)
- CVE-2026-48316ColdFusion | Improper Input Validation (CWE-20)
- CVE-2026-48313ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- CVE-2026-48285ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
- CVE-2026-48307ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
- CVE-2026-48363ColdFusion | Uncontrolled Search Path Element (CWE-427)
- CVE-2026-48277ColdFusion | Improper Input Validation (CWE-20)
- CVE-2026-48364ColdFusion | Uncontrolled Search Path Element (CWE-427)
- CVE-2026-48314ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- CVE-2026-48283ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
- CVE-2026-48276ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
- CVE-2026-48282Adobe ColdFusion Path Traversal Vulnerability
- CVE-2026-48281ColdFusion | Improper Input Validation (CWE-20)
Source and provenance
Original title: Security update available for Adobe ColdFusion | APSB26-68. Captured 27 Sept 2026, 14:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗