PT-2026-48275 · Adobe · Coldfusion
CVE-2026-47960
·
Published
2026-06-09
·
Updated
2026-08-26
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ColdFusion versions 2023.19 and earlier
ColdFusion versions 2025.8 and earlier
Description
An Improper Restriction of XML External Entity Reference (XXE) allows arbitrary file system read. This issue enables an attacker to access sensitive files and directories outside the intended access scope. Exploitation requires user interaction, specifically that a victim opens a malicious file. XXE is a type of attack where an application processes XML input containing a reference to an external entity, which can be used to disclose internal files.
Recommendations
Update ColdFusion versions 2023.19 and earlier to a patched version.
Update ColdFusion versions 2025.8 and earlier to a patched version.
Fix
DoS
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion