CVE List

ZDI-26-070

Low

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe ColdFusion. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-61808.

Published February 6, 2026.

Affected software

Get alerts for Adobe Coldfusion

Reference links