CVE-2026-27282
Adobe ColdFusion, coldfusion
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.
- CVSS
- 7.5
- EPSS
- 0.69% 49.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.15