tag: Coldfusion · 1 items
- Engineer — Plan: CVSS 10.0 OS command injection in ColdFusion and companion critical flaws in Commerce and Campaign Classic warrant prioritized patching this sprint. No KEV listing or public PoC yet, but severity justifies treating this ahead of routine patch cycles — apply Adobe’s August updates to all three products immediately.
- SOC/IR — Skip
- Leader — Skip
- Signals: CVE-2026-48362 — CISA KEV: not listed, EPSS n/a, no public PoC found