
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71386 is a Cross-Site Scripting (XSS) vulnerability (CWE-79) in Adobe ColdFusion that can result in arbitrary code execution in the context of the current user. It affects Adobe ColdFusion 2023 (all updates through 2023 Update 22) and ColdFusion 2025 (all updates through 2025 Update 11). The vulnerability was published on August 11, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), meaning user-controllable input is not properly sanitized before being rendered in a web page context. The attack vector is Adjacent Network (AV:A), meaning the attacker must be on the same network segment as the vulnerable administrative interface, which is restricted to an administrative network zone by default. Exploitation requires user interaction — specifically, a victim must open a malicious file — and results in a changed scope, allowing the attacker to impact resources beyond the vulnerable component itself. No public proof-of-concept code has been identified (GitHub Advisory, Adobe Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, with a changed scope indicating that resources beyond the ColdFusion component itself may be compromised. An unauthenticated attacker on the adjacent network can execute arbitrary code in the context of the current user by tricking them into opening a malicious file, potentially enabling full administrative compromise, data exfiltration, or service disruption. Given that the vulnerable component resides in the administrative network zone, exploitation could grant access to sensitive configuration data and administrative functions (GitHub Advisory, Adobe Advisory).
As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.295% (22nd percentile), indicating a low near-term probability of exploitation. Exploitation is not automatable due to the required user interaction and adjacent network access preconditions (GitHub Advisory, Adobe Advisory).
Adobe has released patched versions addressing this vulnerability: ColdFusion 2023 Update 23 and ColdFusion 2025 Update 12. Organizations should apply these updates immediately. As a workaround, restrict network access to the ColdFusion administrative interface to trusted hosts only, and implement web application firewall (WAF) rules to detect and block XSS payloads. User awareness training to prevent opening untrusted files is also recommended (Adobe Advisory, GitHub Advisory).
The vulnerability was covered by several cybersecurity news outlets and threat intelligence platforms following Adobe's August 2026 patch release. CyberSecurityNews and GBHackers reported on the broader set of Adobe ColdFusion vulnerabilities addressed in the August 2026 patch cycle. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products could allow for arbitrary code execution. FortiGuard and Check Point also added detection coverage for this CVE in their IPS signature updates.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."