CVE-2026-71386

8.8

Adobe · ColdFusion

A Cross-site Scripting (XSS) vulnerability in Adobe ColdFusion could allow an attacker to execute arbitrary code in the context of the current user.

Executive summary

Adobe ColdFusion is susceptible to a Cross-site Scripting vulnerability that may allow an attacker to execute arbitrary code in the context of an authenticated or interacting user.

Vulnerability

The software contains a Cross-site Scripting vulnerability that permits the injection of malicious scripts. This flaw can be triggered over an adjacent network and requires user interaction to facilitate arbitrary code execution.

Business impact

Exploitation of this XSS vulnerability could allow an attacker to hijack user sessions or execute malicious scripts in the context of the application. With a CVSS score of 8.8, this presents a high risk of data theft or unauthorized administrative actions, which could severely impact the confidentiality and integrity of the affected platform.

Remediation

Immediate Action: Update Adobe ColdFusion to version 2025.0.12 or 2023.0.23 as provided in the vendor security advisory.

Proactive Monitoring: Review web application logs for suspicious script injection attempts or anomalous requests targeting ColdFusion administrative interfaces.

Compensating Controls: Utilize a Web Application Firewall to block common XSS payloads and sanitize incoming HTTP requests to the application.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations running Adobe ColdFusion must apply the provided updates immediately to remediate the Cross-site Scripting vulnerability. Prompt patching is essential to prevent potential session hijacking and code execution risks within the application environment.

More Adobe CVEs