CVE-2026-76190
largeEval Injection in Adobe ColdFusion Allows Remote Arbitrary Code Execution
Adobe ColdFusion is vulnerable to an eval injection flaw (CWE-95) in which directives are not properly neutralized before dynamically evaluated code is processed, allowing an attacker to execute arbitrary code in the context of the user running ColdFusion. The attack path is network-based and, per the CVSS vector, requires no privileges and no user interaction; the changed-scope designation indicates impact can extend beyond the vulnerable component. A successful attacker gains code execution on the ColdFusion server, with the CVSS scoring emphasizing a high integrity impact. Organizations running affected Adobe ColdFusion releases are exposed, though the source data does not specify version ranges, so administrators should consult Adobe's security bulletin for exact affected and fixed builds. As of this analysis there is no known public proof-of-concept, no entry in CISA's KEV, and EPSS estimates roughly a 1% chance of exploitation within 30 days.
What to do: Inventory all ColdFusion instances and prioritize internet-facing ones for immediate patching with Adobe's fix for CVE-2026-76190 as directed in the Adobe Security Bulletin (no specific versions are given in this data). As interim hardening, audit code paths that dynamically evaluate user-controlled input (CWE-95) and restrict external access to ColdFusion endpoints where feasible. Monitor Adobe PSIRT and CISA advisories, since EPSS indicates limited but non-trivial near-term exploitation risk.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
- Weakness
- CWE-95
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.