Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

Published 5 Sep 2026Updated 5 Sep 202617 sources
CVSS 10.0 ✓ VERIFIED REFERENCE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.