
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76000 is an Uncontrolled Resource Consumption vulnerability (CWE-400) in Adobe ColdFusion that can lead to application denial-of-service. An unauthenticated attacker on an adjacent network can exploit this vulnerability to exhaust system resources without any user interaction. Affected versions include ColdFusion 2025 (update 12 and earlier) and ColdFusion 2023 (update 23 and earlier). Adobe disclosed and patched this vulnerability on September 8, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning ColdFusion fails to properly control the allocation and maintenance of limited system resources when processing certain requests. The attack vector is adjacent network (AV:A), requiring the attacker to be on the same network segment or logical network as the target, with no privileges or user interaction required. Attack patterns associated with this vulnerability include XML Ping of the Death (CAPEC-147) and Regular Expression Exponential Blowup (CAPEC-492), suggesting the flaw may involve malformed XML or regex-based input that triggers excessive resource consumption. No public proof-of-concept code has been identified (Adobe Advisory, GitHub Advisory).
Successful exploitation results in an application denial-of-service condition by exhausting system resources on the affected ColdFusion server. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot read or modify data through this vulnerability alone. Affected deployments include ColdFusion 2025 (≤ update 12) and ColdFusion 2023 (≤ update 23) on all platforms (Adobe Advisory, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the time of disclosure. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.33%, placing it in the 26th percentile for exploitation likelihood within 30 days. CVE-2026-76000 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Adobe Advisory, GitHub Advisory).
Adobe has released security updates addressing this vulnerability: ColdFusion 2025 users should apply Update 13 or later, and ColdFusion 2023 users should apply Update 24 or later. As an interim measure, implement network segmentation to restrict access to ColdFusion instances from untrusted adjacent networks, reducing the attack surface given the adjacent-network attack vector. Monitor ColdFusion instances for unusual resource consumption patterns that may indicate exploitation attempts (Adobe Advisory).
The CIS issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution and denial-of-service, recommending prompt patching. FortiGuard also tracked the vulnerability in its IPS update feed shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."