CVE-2026-48325EPSS p44.3%
CVE-2026-48325CVE-2026-48325
adobe / coldfusion
Description
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Scoring
| CVSS | 9.3 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 0.55% probability of exploitation · percentile 44.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |