CVE-2026-76000
Undergoing Analysis Undergoing Analysis - In Progress

Uncontrolled Resource Consumption in Adobe ColdFusion

Vulnerability report for CVE-2026-76000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-18

Assigner: Adobe Systems Incorporated

Description

ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-18
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 37 associated CPEs
Vendor Product Version / Range
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Uncontrolled Resource Consumption issue in Adobe ColdFusion. It allows an attacker to exploit the system by consuming excessive resources, leading to a denial-of-service condition where the application becomes unavailable.

Detection Guidance

Detecting uncontrolled resource consumption in ColdFusion requires monitoring system resource usage and ColdFusion-specific logs. Check for unusually high CPU, memory, or network usage on the ColdFusion server. Review ColdFusion logs for repeated requests or errors indicating resource exhaustion. Use system monitoring tools like top, htop, or perfmon for resource tracking.

Impact Analysis

The vulnerability can cause your ColdFusion application to crash or become unresponsive due to resource exhaustion. This may disrupt services, leading to downtime and potential loss of access for legitimate users.

Mitigation Strategies

Apply the latest security patches from Adobe for ColdFusion immediately. Limit network access to the ColdFusion administration interface. Monitor and restrict resource usage by configuring ColdFusion to limit concurrent requests. Implement rate limiting and request throttling to prevent resource exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart