Adobe Coldfusion — CVE-2026-48320 (Critical)
Summary
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 8.5) in Adobe Coldfusion. Patch or mitigate promptly. EPSS percentile: 89%.
Operator check
Review CVE-2026-48320 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 8.5. EPSS probability: 3.8%; percentile: 89%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.