Skip to content
AdobeCVE-2026-76190

Adobe ColdFusion: code execution

High8.6CVE-2026-76190 · Published Sep 8, 2026 · updated Sep 18, 2026

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Adobe advisory

Affected versions

PackageAffectedFixed in
ColdFusion 2023
Product
<= 23No fix yet
ColdFusion 2025
Product
<= 12No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-95

More Adobe advisories

All Adobe
Advisory
Adobe Acrobat 2024: heap buffer overflow
Medium5.5Sep 8
Adobe Acrobat 2024: prototype pollution
High8.2Sep 8
Adobe Acrobat 2024: improper authorization
High8.8Sep 8
Adobe Acrobat 2024: improper authorization
Medium6.3Sep 8
Adobe Acrobat 2024: resource exhaustion
Medium5.5Sep 8
Adobe Acrobat 2024: use after free
High7.8Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.