CVE-2026-75993

Adobe Security Bulletin APSB26-119 — Coldfusion

Beschreibung

ColdFusion ist von einer reflektierten Cross-Site Scripting (XSS)-Sicherheitslücke betroffen. Ein Angreifer könnte diese Sicherheitslücke ausnutzen, um schädliche Skripte in eine Webseite einzuschleusen und dadurch möglicherweise erhöhten Zugriff oder Kontrolle über das Konto oder die Sitzung des Opfers zu erlangen. Die Ausnutzung dieses Problems erfordert Benutzerinteraktion, da ein Opfer eine schädliche Datei öffnen muss. Der Geltungsbereich wurde geändert.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.5
Quelle: nvd-v3
30.4 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 19:37 UTC
CWE-79

Weakness-Klassen (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-75993","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-75993","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-09-10 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-75993","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-08 20:18 UTC· psirt@adobe.com
    • Description: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
    • CVSS V3.1: AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    • CWE: CWE-79
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/75xxx/CVE-2026-75993.json">CVE-2026-75993</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Adobe

    ColdFusion2023.0.23

  • Adobe

    ColdFusion2025.0.12

  • Adobe

    ColdFusion2023 <2023.0.24

  • Adobe

    ColdFusion2025 <2025.0.13

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-75993