Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3254 articles · 211237 vulns · 37/41 feeds (7d)
← Back to list
7.1
CVE-2026-83961PATCHED
adobe · coldfusion

ColdFusion | Improper Authentication (CWE-287)

Description

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobecoldfusion0, 0

References

  • https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html(vendor-advisory)

Related News (1 articles)

Tier C
VulDB5d ago
CVE-2026-83961 | Adobe ColdFusion improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.1 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
2025.0.122023.0.23
CWECWE-287
PublishedSep 3, 2026
Last enriched5d ago
Trending Score17
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-75650EXPKEV
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Trending: 140
HIGHCVE-2026-83959
Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
Trending: 17
HIGHCVE-2026-48388
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
Trending: 15
CRITICALCVE-2026-76197
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13
CRITICALCVE-2026-76195
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 3, 2026
Discovered by ZDM
Sep 3, 2026
Patch Available
Sep 3, 2026