Improper Input Validation — CVE-2026-48277, CVE-2026-48281, CVE-2026-48315.

Release Date: 6th July 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

ColdFusion doesn't adequately sanitize attacker-supplied input in certain request paths.

 

References

  1. https://www.cisa.gov/news-events/bulletins/sb26-187
  2. https://www.cve.org/CVERecord?id=CVE-2026-48277
  3. https://www.cve.org/CVERecord?id=CVE-2026-48281
  4. https://www.cve.org/CVERecord?id=CVE-2026-48315