Executive brief
Adobe ColdFusion, a web application server used by enterprises to build and deploy dynamic websites and services, is vulnerable to a denial-of-service attack via uncontrolled resource consumption. An attacker can exploit this remotely without user interaction to exhaust server resources, causing the application to become unavailable and disrupting business operations.
Technical details
ColdFusion contains an uncontrolled resource consumption vulnerability (CWE-400) in its request parsing or template processing logic. The vulnerability allows an attacker to send specially crafted requests that consume excessive CPU, memory, or other system resources, leading to denial-of-service. No user interaction is required, and the attack is exploitable over the network against any exposed ColdFusion instance. The vulnerability can be triggered by an unauthenticated remote attacker. Adobe has issued a security patch to address this issue.
Affected products
- Adobe ColdFusion
Timeline
- 2026-09-08: disclosed