Junglewise Threat Intelligence

CVE-2026-76190: Adobe ColdFusion code injection in dynamically evaluated code

CVE-2026-76190 · Severity: high · CVSS 8.6 · Published 2026-09-08

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is a web application server used to build and deploy dynamic websites and applications. A code injection vulnerability allows attackers to execute arbitrary code on servers running the affected version without requiring user interaction, potentially compromising the entire application and underlying system.

Technical details

The vulnerability is an improper neutralization of directives in dynamically evaluated code (eval injection) in Adobe ColdFusion. The vulnerability allows an attacker to inject and execute arbitrary code through unsafe evaluation of user-supplied or attacker-controlled input. No user interaction is required for exploitation, and the attack is network-accessible. An attacker can achieve remote code execution in the context of the ColdFusion server process. Patches are expected to be available from Adobe.

Affected products

  • Adobe ColdFusion

Timeline

  • 2026-09-08: disclosed

References

Related threats