CVE-2026-48328
Adobe ColdFusion 2025, ColdFusion 2023, coldfusion
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
- CVSS
- 7.7
- EPSS
- 0.53% 41.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15