CVE-2026-71386
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-71386 is a Cross-Site Scripting (XSS) vulnerability (CWE-79) in Adobe ColdFusion that can result in arbitrary code execution in the context of the current user. It affects Adobe ColdFusion 2023 (all updates through 2023 Update 22) and ColdFusion 2025 (all updates through 2025 Update 11). The vulnerability was published on August 11, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), meaning user-controllable input is not properly sanitized before being rendered in a web page context. The attack vector is Adjacent Network (AV:A), meaning the attacker must be on the same network segment as the vulnerable administrative interface, which is restricted to an administrative network zone by default. Exploitation requires user interaction — specifically, a victim must open a malicious file — and results in a changed scope, allowing the attacker to impact resources beyond the vulnerable component itself. No public proof-of-concept code has been identified (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, with a changed scope indicating that resources beyond the ColdFusion component itself may be compromised. An unauthenticated attacker on the adjacent network can execute arbitrary code in the context of the current user by tricking them into opening a malicious file, potentially enabling full administrative compromise, data exfiltration, or service disruption. Given that the vulnerable component resides in the administrative network zone, exploitation could grant access to sensitive configuration data and administrative functions (GitHub Advisory, Adobe Advisory).

Exploitability

As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.295% (22nd percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable due to the required user interaction and adjacent network access preconditions (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Reconnaissance: Identify Adobe ColdFusion administrative interfaces accessible on the adjacent network segment, targeting versions up to ColdFusion 2023 Update 22 or ColdFusion 2025 Update 11.
  2. Craft malicious file: Prepare a file containing a malicious XSS payload designed to execute arbitrary JavaScript or code when rendered by the ColdFusion administrative interface.
  3. Deliver the file: Use social engineering or other means to convince an authenticated administrative user on the adjacent network to open or upload the malicious file through the ColdFusion admin interface.
  4. Trigger XSS execution: When the victim opens the malicious file, the unsanitized input is rendered in the administrative web page context, causing the injected script to execute in the victim's browser session.
  5. Achieve code execution: The executed script runs with the privileges of the current user's session, potentially enabling session hijacking, credential theft, further lateral movement, or arbitrary actions within the administrative interface (GitHub Advisory, Adobe Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the ColdFusion server to external or unusual IP addresses originating from the administrative interface; anomalous HTTP requests to the ColdFusion admin panel from adjacent network hosts.
  • Logs: ColdFusion access logs showing file upload or open events followed by unusual script execution activity; JavaScript-related errors or unexpected redirects logged in the administrative interface.
  • File System: Presence of unexpected or newly created files in the ColdFusion web root or administrative directories; files with embedded script tags or encoded payloads.
  • Process: Unusual child processes spawned by the ColdFusion service process; unexpected network connections initiated by the ColdFusion Java process.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: ColdFusion 2023 Update 23 and ColdFusion 2025 Update 12. Organizations should apply these updates immediately. As a workaround, restrict network access to the ColdFusion administrative interface to trusted hosts only, and implement web application firewall (WAF) rules to detect and block XSS payloads. User awareness training to prevent opening untrusted files is also recommended (Adobe Advisory, GitHub Advisory).

Community reactions

The vulnerability was covered by several cybersecurity news outlets and threat intelligence platforms following Adobe's August 2026 patch release. CyberSecurityNews and GBHackers reported on the broader set of Adobe ColdFusion vulnerabilities addressed in the August 2026 patch cycle. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products could allow for arbitrary code execution. FortiGuard and Check Point also added detection coverage for this CVE in their IPS signature updates.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71384CRITICAL9.6
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71387HIGH8.8
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71386HIGH8.8
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-48440HIGH8.1
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026
CVE-2026-71383HIGH7.3
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management