Adobe Coldfusion — CVE-2026-48320 (Critical)

Date Jul 14, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Adobe · Coldfusion
CVE CVE-2026-48320
Critical vendor advisory CVE-2026-48320

Summary

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 8.5) in Adobe Coldfusion. Patch or mitigate promptly. EPSS percentile: 89%.

Operator check

Review CVE-2026-48320 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 8.5. EPSS probability: 3.8%; percentile: 89%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.