CVE-2026-48440 ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends… cve.org/CVERecord?id=C…
Official account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on cve.org
Joined January 2017
- CVE-2026-48376 is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this … cve.org/CVERecord?id=C…
- CVE-2026-21269 is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fi… cve.org/CVERecord?id=C…
- CVE-2026-48375 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this… cve.org/CVERecord?id=C…
- CVE-2026-48384 ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exp… cve.org/CVERecord?id=C…

