AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-2861

CRITICAL · CVSS 9.8 EPSS 99.72% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-08-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2022-03-25

Required action: Apply updates per vendor instructions.

CVE
CVE-2010-2861
Severity
CRITICAL
CVSS
9.8
EPSS
99.72%

Original NVD Description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.