SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76002

MEDIUM · CVSS 6.1 EPSS 0.73%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

ColdFusion is vulnerable to a reflected Cross-Site Scripting (XSS) flaw that allows attackers to execute malicious JavaScript in the victim's browser by tricking them into visiting a specially crafted URL. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive information. Organizations using ColdFusion should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-76002
Severity
MEDIUM
CVSS
6.1
EPSS
0.73%
Java

Original NVD Description

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.