Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75999
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-75999 is an Improper Input Validation vulnerability (CWE-20) in Adobe ColdFusion that could result in arbitrary code execution in the context of the current user. It affects ColdFusion 2025 (update 12 and earlier) and ColdFusion 2023 (update 23 and earlier) on all platforms. Adobe disclosed and patched the vulnerability on September 8, 2026. It carries a CVSS v3.1 base score of 8.4 (High) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability stems from insufficient input validation within a ColdFusion component that is restricted to an administrative network zone by default (CWE-20). A low-privileged attacker with adjacent network access can exploit this flaw by delivering a malicious file that a victim must open, triggering arbitrary code execution in the context of the current user. The attack complexity is low, but exploitation requires both adjacency to the administrative network and user interaction. The scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation results in full compromise of confidentiality, integrity, and availability of the affected ColdFusion instance, as all three impact metrics are rated High. Because the scope is changed, an attacker may be able to pivot beyond the ColdFusion process to affect other components or systems within the administrative network zone. Sensitive data accessible to the ColdFusion service account — including application data, credentials, and configuration files — could be exposed or manipulated (Adobe Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Adobe Advisory). The EPSS score is approximately 0.367%, placing it in the 30th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" at this time. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify ColdFusion 2023 or 2025 instances accessible on an administrative network segment using network scanning tools (e.g., Nmap) or asset inventory systems, targeting versions at or below update 12 (2025) or update 23 (2023).
  2. Gain low-privileged access: Obtain or use existing low-privileged credentials on the adjacent administrative network to position for the attack.
  3. Craft malicious file: Prepare a specially crafted file that exploits the improper input validation flaw in the targeted ColdFusion component — the specific file type and payload format have not been publicly disclosed.
  4. Deliver malicious file: Deliver the crafted file to a victim user on the administrative network via phishing, shared network storage, or another social engineering vector.
  5. Trigger exploitation: Induce the victim to open the malicious file, causing ColdFusion to process the malformed input without proper validation.
  6. Achieve code execution: Arbitrary code executes in the context of the ColdFusion process user, potentially enabling data exfiltration, backdoor installation, or lateral movement within the administrative network (Adobe Advisory, GitHub Advisory).

Mitigation and workarounds

Adobe has released security updates addressing this vulnerability: ColdFusion 2025 users should apply Update 13 or later, and ColdFusion 2023 users should apply Update 24 or later (Adobe Advisory). As a configuration-based mitigation, ensure the ColdFusion administrative interface remains restricted to trusted administrative network zones and is not exposed to untrusted networks. Additionally, educate users to avoid opening files from untrusted or unexpected sources, particularly within administrative environments.

Community reactions

The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). FortiGuard also tracked the vulnerability in its IPS update feed shortly after disclosure. No significant independent researcher commentary or social media discussion has been identified beyond standard aggregation and advisory coverage.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76190HIGH8.6
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75999HIGH8.4
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75998HIGH7.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76000MEDIUM6.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76002MEDIUM6.1
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management