CVE-2026-29519General

LOWCVSS 6.2 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or JavaScript payloads within the request path. Attackers can craft a malicious URL containing injected script content that is reflected in the server's response without proper output encoding, enabling session hijacking or unauthorized actions against the Lucee administrative interface when a victim visits the crafted link.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-11: 2Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 107-11
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-29519 (CVSS 8.2): reflected XSS in Lucee CFML 5.3.x-7.0.x. Check instances and apply updates. https://nvd.nist.gov/vuln/detail/CVE-2026-29519 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/CD4ALMo62R

    Post summary

    The tweet announces CVE‑2026‑29519—a reflected XSS in Lucee CFML—and advises checking instances and applying updates.

    0000037
    89 followersView on X
  • VulDB 🛡@vuldb
    General

    It is possible to see elevated activities targeting Lucee (CVE-2026-29519) https://vuldb.com/vuln/377487/cti

    Post summary

    The post notes that there may be increased activity against Lucee for CVE-2026-29519, but it does not provide evidence of exploitation, PoC, or patches.

    00000131
    2.3K followersView on X

Explore more