Junglewise Threat Intelligence

CVE-2026-75999: Adobe ColdFusion improper input validation remote code execution

CVE-2026-75999 · Severity: high · CVSS 8.4 · Published 2026-09-08

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is an enterprise application development platform used to build and deploy web applications. An improper input validation vulnerability allows a low-privileged attacker to execute arbitrary code with the privileges of the current user. While the vulnerable component is restricted to administrative networks by default, exploitation requires a victim to open a malicious file, creating a foothold for code execution and potential compromise of the application server.

Technical details

ColdFusion contains an improper input validation vulnerability in an administrative-restricted component that permits arbitrary code execution. The vulnerability is triggered when a victim opens a malicious file, bypassing input validation controls and allowing an authenticated attacker with low privileges to inject and execute arbitrary code in the context of the application. The scope changes as a result of successful exploitation. No active exploitation in the wild has been reported as of the advisory date. Patches are expected to be available from Adobe via security bulletin APSB26-119.

Affected products

  • Adobe ColdFusion

Timeline

  • 2026-09-08: disclosed

References

Related threats