CVE-2026-48332
Adobe ColdFusion 2025, ColdFusion 2023, coldfusion
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
- CVSS
- 7.7
- EPSS
- 10.7% 95.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15