CVE-2026-27307: ColdFusion | Uncontrolled Resource Consumption (CWE-400)
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27307?
CVE-2026-27307 is classified as a high-severity vulnerability that can lead to denial-of-service in affected ColdFusion versions.
How do I fix CVE-2026-27307?
To fix CVE-2026-27307, upgrade to the latest version of Adobe ColdFusion that addresses this vulnerability.
Which versions of ColdFusion are affected by CVE-2026-27307?
ColdFusion versions 2023.18, 2025.6 and earlier are affected by CVE-2026-27307.
What is the impact of exploiting CVE-2026-27307?
Exploiting CVE-2026-27307 can lead to uncontrolled resource consumption, potentially causing application denial-of-service.
Who can exploit CVE-2026-27307?
A high-privileged attacker can exploit CVE-2026-27307 to exhaust system resources on affected ColdFusion servers.