Junglewise Threat Intelligence

CVE-2026-27307: Adobe ColdFusion uncontrolled resource consumption

CVE-2026-27307 · Severity: low · CVSS 2.4 · Published 2026-04-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building web applications, is affected by a vulnerability that allows an authorized user to slow down or crash the application. By consuming excessive system resources, a high-privileged attacker can cause a denial-of-service, impacting the availability of the service for other users. This issue does not require any interaction from other users to be exploited.

Technical details

Adobe ColdFusion is vulnerable to uncontrolled resource consumption (CWE-400) in versions 2023.18, 2025.6 and earlier. The vulnerability allows a high-privileged attacker with adjacent network access to exhaust system resources without any user interaction. This can lead to a partial denial-of-service (DoS) by significantly reducing application performance or causing it to become unresponsive. The CVSS score is low (2.4) primarily because the attack requires high privileges and is limited to the adjacent network. Adobe has released security updates to address this issue in advisory APSB26-38.

Affected products

  • Adobe ColdFusion 2023.18, 2025.6 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe published APSB26-38

References

Related threats