# CVE-2026-48386

## Summary

- **CVE ID:** CVE-2026-48386
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-327
- **Published:** Aug 11, 2026
- **Last Modified:** Aug 28, 2026

## Description

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.

## Affected Products

- Adobe — ColdFusion 2025 (0)
- Adobe — ColdFusion 2025 (2025.0.12)
- Adobe — ColdFusion 2023 (0)
- Adobe — ColdFusion 2023 (2023.0.23)

## References

- [CNA](https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.81%
- **EPSS Percentile:** 54.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._