ZeroHour

CVE-2026-48325

CVSS 3.1
9.3 critical
EPSS
<1%p44
Published
()
Modified
Description

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-306
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news