ZeroHour

CVE-2026-75999

large

Improper Input Validation in Adobe ColdFusion Enables Arbitrary Code Execution

CVSS 3.1
8.4 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Adobe ColdFusion contains an improper input validation flaw (CWE-20) that allows a low-privileged attacker to execute arbitrary code in the context of the current user. The vulnerable component is restricted to an administrative network zone by default, and exploitation requires user interaction in which a victim opens a malicious file. The CVSS vector (adjacent attack vector, low privileges required, and a scope change) indicates the attack crosses a security boundary, so the attacker needs some access to or foothold in the administrative network zone. Any organization running Adobe ColdFusion whose administrative zone is reachable beyond trusted admin hosts, or whose users in that zone open untrusted files, is potentially affected. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns a modest 0.4% probability of exploitation within 30 days.

What to do: Watch Adobe's security bulletin for the patched ColdFusion release and apply the update promptly when published; no fixed versions are named in the data available here. In the interim, verify that the affected administrative network zone component is not reachable from user or internet-facing networks and that hosts in that zone are not used to open untrusted files. Restricting access to ColdFusion administrative endpoints to dedicated admin hosts is the key mitigation.

Affected
Adobe ColdFusion
Estimated exposure
largeon the order of tens of thousands of ColdFusion server deployments (realistically exploitable subset likely smaller) — Historical internet-wide scans have shown tens of thousands of Adobe ColdFusion instances, but this flaw's requirements for administrative-zone adjacency and user interaction mean the practically exploitable subset is a fraction of that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Weakness
CWE-20
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.