ZeroHour

CVE-2026-75993

moderate

Reflected Cross-Site Scripting (XSS) in Adobe ColdFusion

CVSS 3.1
8.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Adobe ColdFusion contains a reflected Cross-Site Scripting vulnerability (CWE-79) with a changed-scope rating, meaning the flaw in the ColdFusion component impacts the victim's browser session rather than ColdFusion itself. Exploitation requires user interaction: a victim must open a malicious file (or crafted link), which then causes injected script to execute in the context of the affected web application. A successful attack could give the attacker elevated access or control over the victim's account or session, potentially allowing actions within the application as that user. Organizations running Adobe ColdFusion and the users of web applications served by those servers are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS puts 30-day exploitation probability at about 0.4% (30th percentile) and the issue is not in CISA KEV.

What to do: No affected or fixed version ranges are included in the available data, so consult Adobe's security bulletin (apsb) for this CVE to identify affected releases and apply the patched update as soon as it is available. In the interim, reduce exposure by restricting network access to ColdFusion-hosted applications and administrative endpoints, and remind users not to open untrusted files or links that reference their ColdFusion applications.

Affected
Adobe ColdFusion
Estimated exposure
moderateon the order of tens of thousands of internet-visible ColdFusion server instances — Adobe does not publish install counts, but public internet-wide scans have historically surfaced tens of thousands of exposed ColdFusion servers, and the product remains a persistent but niche enterprise application server, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Weakness
CWE-79
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.