
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75999 is an Improper Input Validation vulnerability (CWE-20) in Adobe ColdFusion that could result in arbitrary code execution in the context of the current user. It affects ColdFusion 2025 (update 12 and earlier) and ColdFusion 2023 (update 23 and earlier) on all platforms. Adobe disclosed and patched the vulnerability on September 8, 2026. It carries a CVSS v3.1 base score of 8.4 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability stems from insufficient input validation within a ColdFusion component that is restricted to an administrative network zone by default (CWE-20). A low-privileged attacker with adjacent network access can exploit this flaw by delivering a malicious file that a victim must open, triggering arbitrary code execution in the context of the current user. The attack complexity is low, but exploitation requires both adjacency to the administrative network and user interaction. The scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).
Successful exploitation results in full compromise of confidentiality, integrity, and availability of the affected ColdFusion instance, as all three impact metrics are rated High. Because the scope is changed, an attacker may be able to pivot beyond the ColdFusion process to affect other components or systems within the administrative network zone. Sensitive data accessible to the ColdFusion service account — including application data, credentials, and configuration files — could be exposed or manipulated (Adobe Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Adobe Advisory). The EPSS score is approximately 0.367%, placing it in the 30th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" at this time. No threat actor attribution has been reported.
Adobe has released security updates addressing this vulnerability: ColdFusion 2025 users should apply Update 13 or later, and ColdFusion 2023 users should apply Update 24 or later (Adobe Advisory). As a configuration-based mitigation, ensure the ColdFusion administrative interface remains restricted to trusted administrative network zones and is not exposed to untrusted networks. Additionally, educate users to avoid opening files from untrusted or unexpected sources, particularly within administrative environments.
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). FortiGuard also tracked the vulnerability in its IPS update feed shortly after disclosure. No significant independent researcher commentary or social media discussion has been identified beyond standard aggregation and advisory coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."