BlackTreeCVE IntelligenceJanuary 2026 Patch TuesdayAPSB26-12Normal patch window
Adobe · APSB26-12
Linked CVE review
Update Adobe ColdFusion to the fixed Adobe release
- Linked CVEs
- 1
- Confirmed exploited
- 0
- PoC or lab evidence
- 1
- Maximum CVSS
- 8.4
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
1 of 1 linked CVEs shown
Confirmed exploitedCVSS above 9.0
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2025-66516 PoC or lab evidence Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedCritical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability | 8.4 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedCISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material. | EPSS: 89.0% · 99.8th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |