Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75998
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-75998 is an Improper Access Control vulnerability in Adobe ColdFusion that allows unauthenticated remote attackers to perform arbitrary file system reads, accessing sensitive files and directories outside the intended access scope. It affects ColdFusion 2025 (update 12 and earlier) and ColdFusion 2023 (update 23 and earlier) on all platforms. Adobe disclosed and patched the vulnerability on September 8, 2026, via security bulletin APSB26-119. It carries a CVSS v3.1 base score of 7.5 (High) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), meaning ColdFusion fails to properly restrict access to file system resources from unauthorized actors. An unauthenticated attacker can send crafted network requests to a vulnerable ColdFusion instance to read arbitrary files and directories that should be outside the accessible scope, without requiring any user interaction or elevated privileges. The attack vector is network-based with low complexity, making it straightforward to exploit at scale (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact, enabling an unauthenticated attacker to read arbitrary files and restricted directories on the ColdFusion server. This could expose sensitive configuration files (including database credentials, API keys, and ColdFusion administrator passwords), application source code, and other sensitive data stored on the server. There is no integrity or availability impact, but the exposed credentials could facilitate lateral movement or further compromise of connected systems (Adobe Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Adobe Advisory). The vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation can be scripted without manual interaction. The EPSS score is approximately 0.648%, placing it in the 49th percentile for exploitation probability within 30 days. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Adobe ColdFusion instances running version 2025 update 12 or earlier, or 2023 update 23 or earlier, using tools such as Shodan or Censys by searching for ColdFusion-specific HTTP response headers or default pages.
  2. Craft malicious request: Construct an HTTP request targeting a ColdFusion endpoint that improperly handles file path parameters, exploiting the lack of access control enforcement to reference files outside the web root (e.g., using path traversal sequences or direct file references).
  3. Send unauthenticated request: Submit the crafted request to the vulnerable ColdFusion server without any authentication credentials or session tokens, as no privileges are required.
  4. Retrieve sensitive files: Parse the server response to extract the contents of targeted files such as neo-security.xml, password.properties, web.xml, or other configuration files containing credentials or sensitive application data.
  5. Leverage disclosed data: Use any recovered credentials or configuration details to escalate access to databases, administrative interfaces, or connected systems (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to ColdFusion endpoints containing path traversal sequences (e.g., ../, %2e%2e%2f) or references to system files outside the web root; unexpected outbound connections from the ColdFusion server following such requests.
  • Logs: ColdFusion access logs showing requests to file-handling endpoints with anomalous file path parameters; HTTP 200 responses to requests referencing sensitive system or configuration files; repeated requests from a single IP targeting different file paths.
  • File System: No direct file system artifacts are expected from read-only exploitation, but review for subsequent unauthorized access to configuration files such as neo-security.xml, password.properties, or web.xml that may indicate credential harvesting.
  • Process: Unexpected administrative logins or database connections following exploitation, potentially indicating use of harvested credentials (Adobe Advisory).

Mitigation and workarounds

Adobe has released patches addressing this vulnerability: ColdFusion 2025 users should update to Update 13 or later, and ColdFusion 2023 users should update to Update 24 or later, as detailed in security bulletin APSB26-119. As interim mitigations, administrators should implement network-level controls to restrict access to ColdFusion services to trusted IP ranges, and deploy Web Application Firewall (WAF) rules to detect and block suspicious file path traversal patterns. Reviewing ColdFusion access logs for anomalous file access attempts is also recommended (Adobe Advisory).

Community reactions

The Center for Internet Security (CIS) published an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution and data disclosure, recommending prompt patching (CIS Advisory). Beyond Machines and other security aggregators covered Adobe's September 2026 patch release, highlighting the ColdFusion vulnerabilities as high-priority items for enterprise defenders. No significant independent researcher commentary or social media discussion has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76190HIGH8.6
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75999HIGH8.4
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75998HIGH7.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76000MEDIUM6.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76002MEDIUM6.1
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management