CVE-2026-48440

Adobe Security Bulletin APSB26-90 — Coldfusion

Beschreibung

ColdFusion ist von einer heap-basierten Pufferüberlauf-Schwachstelle betroffen, die zur willkürlichen Codeausführung im Kontext des aktuellen Benutzers führen könnte. Die Ausnutzung hängt von Bedingungen ab, die außerhalb der Kontrolle des Angreifers liegen. Zur Ausnutzung dieser Schwachstelle ist keine Interaktion mit dem Benutzer erforderlich.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.1
Quelle: nvd-v3
49.3 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 16:30 UTC
CWE-122

Weakness-Klassen (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:18 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48440.json">CVE-2026-48440</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html Types: Vendor Advisory
  2. CVE Modified2026-08-11 18:17 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023ColdFusion 2025, ColdFusion 2023
  3. New CVE Received2026-08-11 17:18 UTC· psirt@adobe.com
    • Affected: ColdFusion 2025, ColdFusion 2023
    • Description: ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-122

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-48440