CVE-2026-27308: ColdFusion | Uncontrolled Resource Consumption (CWE-400)
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27308?
CVE-2026-27308 is classified as a high severity vulnerability due to its potential for causing denial-of-service.
How do I fix CVE-2026-27308?
To mitigate CVE-2026-27308, users should upgrade to Adobe ColdFusion version 2023.19 or 2025.7 or later.
What versions of ColdFusion are affected by CVE-2026-27308?
CVE-2026-27308 affects Adobe ColdFusion versions 2023.18, 2025.6, and earlier.
What type of vulnerability is CVE-2026-27308?
CVE-2026-27308 is categorized as an Uncontrolled Resource Consumption vulnerability, which can lead to application denial-of-service.
Who can exploit CVE-2026-27308?
This vulnerability can be exploited by a high-privileged attacker to exhaust system resources.