CVE Record
[ CRITICAL ]CVE-2026-48325
Adobe ColdFusion missing authentication — CVSS 9.3
Missing authentication check in Adobe ColdFusion allows unauthenticated attackers to access protected functionality. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.
- Vendor
- Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- CVSS
- 9.3
- EPSS (exploit probability)
- 0.6%
- Status
- patched
- Published
A missing authentication check in Adobe ColdFusion exposes protected endpoints to unauthenticated remote attackers. The flaw was patched alongside seven other critical vulnerabilities in Adobe’s July 2026 ColdFusion security update.
Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. Missing-authentication vulnerabilities in ColdFusion are historically among the fastest to appear in KEV; treat internet-exposed installations as highest priority.
Source: NVD · Adobe Security Bulletin
