CVE-2025-49535
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access sensitive information or denial of service by bypassing security measures. Exploitation of this issue does not require user interaction and scope is changed. The vulnerable component is restricted to internal IP addresses.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
- EPSS probability
- 0.55%
- CWE
- CWE-611
- Published
- 2025-07-08
- Last modified
- 2026-03-13
Affected products
- Adobe ColdFusion
Weakness type
Related vulnerabilities
- CVE-2026-19596 — OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
- CVE-2026-19614 — XML External Entity (XXE) Injection in CyberELF NanoXML
- CVE-2026-71375 — XXE Vulnerability in Cosminexus Component Container
- CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite
- CVE-2026-17443 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-17444 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-81832 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing