CVE-2017-11286: Adobe ColdFusion
High severity, CVSS 7.5. EPSS: 9.6% chance of exploitation in the next 30 days.
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Affected products
- Adobe ColdFusion: version 11.0 only; version 2016 only
Published 2017-12-01. Last modified 2026-06-17.