Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76190
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-76190 is an Eval Injection vulnerability (CWE-95) in Adobe ColdFusion that allows unauthenticated remote attackers to execute arbitrary code without user interaction. It affects Adobe ColdFusion 2025 (update 12 and earlier) and ColdFusion 2023 (update 23 and earlier). The vulnerability was disclosed and patched on September 8, 2026, via Adobe security advisory APSB26-119. It carries a CVSS v3.1 base score of 8.6 (High) with changed scope (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code — 'Eval Injection'), meaning ColdFusion fails to properly sanitize user-supplied input before passing it to a dynamic code evaluation function. An unauthenticated attacker can send a crafted network request to a vulnerable ColdFusion instance, injecting malicious directives that are evaluated server-side, resulting in arbitrary code execution in the context of the running ColdFusion application. The attack requires no privileges, no user interaction, and has low complexity, making it highly automatable. The changed scope indicator reflects that the impact can extend beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code in the context of the ColdFusion application user, resulting in a high integrity impact. While the CVSS scoring reflects no direct confidentiality or availability impact, arbitrary code execution in practice can enable data exfiltration, web shell deployment, and lateral movement to other systems within the network. The changed scope means the vulnerability can affect resources beyond the ColdFusion component itself, amplifying the potential blast radius (Adobe Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.967% (60th percentile), indicating a moderate near-term exploitation probability relative to other CVEs. The vulnerability is classified as automatable by NVD SSVC analysis, meaning exploitation could be scripted at scale. No threat actor attribution or CISA KEV catalog listing has been reported at this time (GitHub Advisory).

Mitigation and workarounds

Adobe has released security updates addressing this vulnerability: ColdFusion 2025 users should apply Update 13 or later, and ColdFusion 2023 users should apply Update 24 or later, as detailed in Adobe advisory APSB26-119. Administrators should prioritize patching given the unauthenticated, network-accessible nature of the vulnerability with no user interaction required. As a general hardening measure, restrict external access to ColdFusion administrator interfaces and apply network-level controls to limit exposure of ColdFusion instances to untrusted networks (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). FortiGuard also tracked the vulnerability in its IPS update feed shortly after disclosure. Community and media coverage has been limited, consistent with the absence of active exploitation or a public PoC at the time of disclosure.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76190HIGH8.6
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75999HIGH8.4
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-75998HIGH7.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76000MEDIUM6.5
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026
CVE-2026-76002MEDIUM6.1
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management