CVE-2026-75993
moderateReflected Cross-Site Scripting (XSS) in Adobe ColdFusion
Adobe ColdFusion contains a reflected Cross-Site Scripting vulnerability (CWE-79) with a changed-scope rating, meaning the flaw in the ColdFusion component impacts the victim's browser session rather than ColdFusion itself. Exploitation requires user interaction: a victim must open a malicious file (or crafted link), which then causes injected script to execute in the context of the affected web application. A successful attack could give the attacker elevated access or control over the victim's account or session, potentially allowing actions within the application as that user. Organizations running Adobe ColdFusion and the users of web applications served by those servers are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS puts 30-day exploitation probability at about 0.4% (30th percentile) and the issue is not in CISA KEV.
What to do: No affected or fixed version ranges are included in the available data, so consult Adobe's security bulletin (apsb) for this CVE to identify affected releases and apply the patched update as soon as it is available. In the interim, reduce exposure by restricting network access to ColdFusion-hosted applications and administrative endpoints, and remind users not to open untrusted files or links that reference their ColdFusion applications.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.