Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

CVE-2026-75993: ColdFusion reflected cross-site scripting (XSS) vulnerability

A security weakness in ColdFusion is being tracked as CVE-2026-75993. ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.

NIST NVDSep 10, 2026, 4:18 AM UTC3 min readCVE-2026-75993
IN 30 SECONDS

Understand the story quickly

What happenedSource reporting

A security weakness in ColdFusion is being tracked as CVE-2026-75993.

Who or what is affectedSource reporting

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.

Why it mattersSource reporting

An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session.

Defender next stepCDF guidance

Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

The full story

Source-grounded reporting, presented as a continuous narrative.

A security weakness in ColdFusion is being tracked as CVE-2026-75993. ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session.

An attacker could exploit this vulnerability to inject malicious scrip. This is not described as a silent network-only exploit: the published description says a victim has to open or process maliciously crafted content before the vulnerable code path is reached. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

SOURCE EVIDENCE

What the reporting is based on

NIST NVD

CVE-2026-75993: ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scrip

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session.

Open source
CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

CDF ANALYSIS

What this means

Risk depends on whether the affected technology and the affected component are deployed and reachable. Exposure, privilege, business criticality and compensating controls should determine remediation priority.

DEFENDER ACTIONS

What security teams should check now

  • Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-75993 and validate the affected path after remediation.
OPEN QUESTIONS

What is not yet confirmed

  • Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards