ZeroHour

CVE-2026-76190

large

Eval Injection in Adobe ColdFusion Allows Remote Arbitrary Code Execution

CVSS 3.1
8.6 high
EPSS
<1%p60
Published
()
Modified
AI analysis

Adobe ColdFusion is vulnerable to an eval injection flaw (CWE-95) in which directives are not properly neutralized before dynamically evaluated code is processed, allowing an attacker to execute arbitrary code in the context of the user running ColdFusion. The attack path is network-based and, per the CVSS vector, requires no privileges and no user interaction; the changed-scope designation indicates impact can extend beyond the vulnerable component. A successful attacker gains code execution on the ColdFusion server, with the CVSS scoring emphasizing a high integrity impact. Organizations running affected Adobe ColdFusion releases are exposed, though the source data does not specify version ranges, so administrators should consult Adobe's security bulletin for exact affected and fixed builds. As of this analysis there is no known public proof-of-concept, no entry in CISA's KEV, and EPSS estimates roughly a 1% chance of exploitation within 30 days.

What to do: Inventory all ColdFusion instances and prioritize internet-facing ones for immediate patching with Adobe's fix for CVE-2026-76190 as directed in the Adobe Security Bulletin (no specific versions are given in this data). As interim hardening, audit code paths that dynamically evaluate user-controlled input (CWE-95) and restrict external access to ColdFusion endpoints where feasible. Monitor Adobe PSIRT and CISA advisories, since EPSS indicates limited but non-trivial near-term exploitation risk.

Affected
Adobe ColdFusion
Estimated exposure
largetens of thousands (roughly 10,000-50,000) internet-exposed ColdFusion servers, with many additional deployments behind firewalls — Historic internet-wide scans have repeatedly shown tens of thousands of ColdFusion servers publicly reachable, while Adobe publishes no active-install counts and many enterprise deployments sit behind firewalls, making total installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Weakness
CWE-95
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.