All CVEs
Vulnerability intelligence

CVE-2026-27282

CWE-20

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.

CVSS Score
7.5
High
EPSS — Exploit Probability
0.7%
Riskier than 49% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Apr 15, 2026 · latest Apr 15, 2026

Coverage timeline