Official source evidenceAdobeAPSB26-68
Official source article · Adobe

Security update available for Adobe ColdFusion | APSB26-68

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
PublisherAdobe
Article IDAPSB26-68
Verified snapshot27 Sept 2026, 14:00 UTC
Linked CVEs13

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-48315ColdFusion | Improper Input Validation (CWE-20)
  • CVE-2026-48316ColdFusion | Improper Input Validation (CWE-20)
  • CVE-2026-48313ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  • CVE-2026-48285ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
  • CVE-2026-48307ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
  • CVE-2026-48363ColdFusion | Uncontrolled Search Path Element (CWE-427)
  • CVE-2026-48277ColdFusion | Improper Input Validation (CWE-20)
  • CVE-2026-48364ColdFusion | Uncontrolled Search Path Element (CWE-427)
  • CVE-2026-48314ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  • CVE-2026-48283ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  • CVE-2026-48276ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  • CVE-2026-48282Adobe ColdFusion Path Traversal Vulnerability
  • CVE-2026-48281ColdFusion | Improper Input Validation (CWE-20)

Source and provenance

Original title: Security update available for Adobe ColdFusion | APSB26-68. Captured 27 Sept 2026, 14:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗