CVE-2024-20767CISA KEVEPSS p99.9%

CVE-2024-20767Adobe ColdFusion Improper Access Control Vulnerability

Adobe / ColdFusion

Description

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

Scoring

EPSS98.51% probability of exploitation · percentile 99.9% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2024-12-16

(incoming)1

TypeTargetConfidenceTier
KEVEntryAdobe ColdFusion Improper Access Control Vulnerabilitykev-cve-2024-207670%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Adobe ColdFusion Authentication Bypass Vulnerability
CVE
CVE-2025-43564
CVE
CVE-2025-30288
CVE
CVE-2025-43563
CVE
CVE-2025-30281
CVE
Adobe ColdFusion Directory Traversal Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.