Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a resource management flaw. A high-privileged user could intentionally exhaust system resources, causing the application to slow down or become unavailable to others. This could disrupt business operations and impact the performance of hosted web services.
Technical details
Adobe ColdFusion is vulnerable to uncontrolled resource consumption (CWE-400) in versions 2023.18, 2025.6, and earlier. The flaw allows a high-privileged attacker with adjacent network access to exhaust system resources without requiring any user interaction. Successful exploitation results in a partial impact on availability, typically manifesting as application slowdowns or a denial-of-service (DoS) condition. Adobe has addressed this issue in security bulletin APSB26-38.
Affected products
- Adobe ColdFusion 2023.18, 2025.6 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory