Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-48325

Adobe ColdFusion missing authentication — CVSS 9.3

Missing authentication check in Adobe ColdFusion allows unauthenticated attackers to access protected functionality. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.

cat cve-2026-48325.json
Vendor
Adobe
Product
ColdFusion 2023, ColdFusion 2025
CVSS
9.3
EPSS (exploit probability)
0.6%
Status
patched
Published

A missing authentication check in Adobe ColdFusion exposes protected endpoints to unauthenticated remote attackers. The flaw was patched alongside seven other critical vulnerabilities in Adobe’s July 2026 ColdFusion security update.

Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. Missing-authentication vulnerabilities in ColdFusion are historically among the fastest to appear in KEV; treat internet-exposed installations as highest priority.

Source: NVD · Adobe Security Bulletin