PatchSiren cyber security CVE debrief
CVE-2026-75746 Adobe CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:18:22.120Z and has not been modified since then. The NVD entry is currently Analyzed. This critical SQL injection vulnerability in Adobe ColdFusion could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability without requiring user interaction. The vulnerability has a CVSS score of 9.1. Defenders responsible for Adobe ColdFusion installations, especially in contexts where high-privilege users are present, should assess exposure and prioritize verification and potential patching or compens.
- Vendor
- Adobe
- Product
- ColdFusion 2025
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Adobe ColdFusion installations, especially in contexts where high-privilege users are present, should assess exposure and prioritize verification and potential patching or compensating controls.
Why it matters
CVE-2026-75746 is a critical SQL injection vulnerability in Adobe ColdFusion that could lead to arbitrary code execution. Defenders should prioritize verifying exposure, especially in high-privilege contexts, and assess the need for immediate patching or compensating controls. Specific details about affected versions and exploitation are limited, requiring verification from official sources.
- Verify exposure of ColdFusion installations to this SQL injection vulnerability.
- Assess the need for immediate patching or compensating controls given the high CVSS score.
- Monitor for potential exploitation attempts as exploitation does not require user interaction.
- Review and update inventory checks to ensure comprehensive coverage of ColdFusion deployments.
Technical summary
CVE-2026-75746 is a SQL injection vulnerability in Adobe ColdFusion that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability without requiring user interaction. The vulnerability has a CVSS score of 9.1 and is considered critical. Affected versions include ColdFusion 2023 and 2025, along with their updates. The vulnerability allows attackers to execute arbitrary code, potentially leading to system compromise. Defenders should prioritize verifying exposure of ColdFusion installations to this SQL injection vulnerability, especially in contexts where high-privilege users are present.
Defensive priority
Defenders should prioritize verifying exposure of ColdFusion installations to this SQL injection vulnerability, especially in contexts where high-privilege users are present, and assess the need for immediate patching or compensating controls.
Recommended defensive actions
- Verify ColdFusion installations for exposure, especially versions 2023 and 2025, and their updates.
- Assess the need for immediate patching or compensating controls, given the high CVSS score.
- Monitor for potential exploitation attempts, as exploitation does not require user interaction.
- Review and update inventory checks to ensure comprehensive coverage of ColdFusion deployments.
- Perform vulnerability scanning to identify potentially exposed ColdFusion instances.
- Implement additional logging and monitoring for suspicious activity.
- Review and update incident response plans to account for potential exploitation.
Evidence notes
The CVE and NVD records indicate a SQL injection vulnerability in Adobe ColdFusion, which could result in arbitrary code execution. The vulnerability has a CVSS score of 9.1 and is considered critical. However, specific details about affected versions and exploitation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75746 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75746
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75746 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75746
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.