PT-2026-48275 · Adobe · Coldfusion

CVE-2026-47960

·

Published

2026-06-09

·

Updated

2026-08-26

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2023.19 and earlier ColdFusion versions 2025.8 and earlier
Description An Improper Restriction of XML External Entity Reference (XXE) allows arbitrary file system read. This issue enables an attacker to access sensitive files and directories outside the intended access scope. Exploitation requires user interaction, specifically that a victim opens a malicious file. XXE is a type of attack where an application processes XML input containing a reference to an external entity, which can be used to disclose internal files.
Recommendations Update ColdFusion versions 2023.19 and earlier to a patched version. Update ColdFusion versions 2025.8 and earlier to a patched version.

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08386
CVE-2026-47960

Affected Products

Coldfusion