Last seen July 12, 2026

CVE-2026-55255 Privilege Escalation Vulnerability affecting ColdFusion

Evidence indicates that ColdFusion is affected by privilege escalation. Reported affected versions include < 1.9.1. Exploitation evidence is classified as confirmed in the wild.

Technical Severity
High severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that ColdFusion is affected by privilege escalation. Reported affected versions include < 1.9.1. Exploitation evidence is classified as confirmed in the wild.

Why This Matters

The evidence matters to defenders using ColdFusion because it could allow an attacker to gain additional privileges.

Recommended Action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Identify deployments of ColdFusion matching the evidenced affected versions: < 1.9.1.

Exposure

Recommended Response
First Seen

Jul 12, 2026 05:30

Last Seen

Jul 12, 2026 05:30

Exploitation status: CONFIRMED_IN_THE_WILD

Affected versions: < 1.9.1

Primary entities:

Adobe Langflow Microsoft ColdFusion Credential Exposure Remote Code Execution

Authoritative Intelligence

CVE CVE-2026-55255, CVE-2026-48282, CVE-2026-50656 Incident identifier
NVD CVSS 10.0 CRITICAL NVD
FIRST EPSS 0.992 99.9 pct
Fixed Version 1.9.1 Provider-backed
GHSA GHSA-QRPV-Q767-XQQ2 GitHub advisory alias
CWE CWE-639, CWE-22, CWE-59 Weakness classification

Provider evidence: NVD, GitHub Advisory, OSV, CISA KEV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Jul 12, 2026 05:30

    BugSkan first recorded this incident.

  • Week in review: Accenture data breach, great open-source cybersecurity tools - Help Net Security
    Jul 12, 2026 05:30

    helpnetsecurity.com · Vulnerability

Sources

Week in review: Accenture data breach, great open-source cybersecurity tools - Help Net Security

helpnetsecurity.com · Jul 12, 2026 05:30

Attackers are actively exploiting critical vulnerabilities, including Adobe ColdFusion (CVE-2026-48282) and Langflow (CVE-2026-55255) for credential harvesting. Microsoft released fixes for a Windows Defender local privilege escalation flaw (CVE-2026-50656), and ClamAV patched seven scanner bugs, underscoring ongoing patch management challenges.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence