PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75746 Adobe CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:22.120Z and has not been modified since then. The NVD entry is currently Analyzed. This critical SQL injection vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability without requiring user interaction. The vulnerability has a CVSS score of 9.1. Defenders responsible for Adobe ColdFusion installations, especially in contexts where high-privilege users are present, should assess exposure and prioritize verification and potential patching or compens.

Vendor
Adobe
Product
ColdFusion 2025
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-18
Advisory published
2026-09-08
Advisory updated
2026-09-18

Who should care

Defenders responsible for Adobe ColdFusion installations, especially in contexts where high-privilege users are present, should assess exposure and prioritize verification and potential patching or compensating controls.

Why it matters

CVE-2026-75746 is a critical SQL injection vulnerability in Adobe ColdFusion that could lead to arbitrary code execution. Defenders should prioritize verifying exposure, especially in high-privilege contexts, and assess the need for immediate patching or compensating controls. Specific details about affected versions and exploitation are limited, requiring verification from official sources.

  • Verify exposure of ColdFusion installations to this SQL injection vulnerability.
  • Assess the need for immediate patching or compensating controls given the high CVSS score.
  • Monitor for potential exploitation attempts as exploitation does not require user interaction.
  • Review and update inventory checks to ensure comprehensive coverage of ColdFusion deployments.

Technical summary

CVE-2026-75746 is a SQL injection vulnerability in Adobe ColdFusion that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability without requiring user interaction. The vulnerability has a CVSS score of 9.1 and is considered critical. Affected versions include ColdFusion 2023 and 2025, along with their updates. The vulnerability allows attackers to execute arbitrary code, potentially leading to system compromise. Defenders should prioritize verifying exposure of ColdFusion installations to this SQL injection vulnerability, especially in contexts where high-privilege users are present.

Defensive priority

Defenders should prioritize verifying exposure of ColdFusion installations to this SQL injection vulnerability, especially in contexts where high-privilege users are present, and assess the need for immediate patching or compensating controls.

Recommended defensive actions

  • Verify ColdFusion installations for exposure, especially versions 2023 and 2025, and their updates.
  • Assess the need for immediate patching or compensating controls, given the high CVSS score.
  • Monitor for potential exploitation attempts, as exploitation does not require user interaction.
  • Review and update inventory checks to ensure comprehensive coverage of ColdFusion deployments.
  • Perform vulnerability scanning to identify potentially exposed ColdFusion instances.
  • Implement additional logging and monitoring for suspicious activity.
  • Review and update incident response plans to account for potential exploitation.

Evidence notes

The CVE and NVD records indicate a SQL injection vulnerability in Adobe ColdFusion, which could result in arbitrary code execution. The vulnerability has a CVSS score of 9.1 and is considered critical. However, specific details about affected versions and exploitation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75746 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75746

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75746 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75746

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.