← Browse

CVE-2026-27308

Low

No strong exploitation signal.

CVSS base
2.4 LOW
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
EPSS — probability of exploitation (30 days)
2.5%
84.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-400
Published 2026-04-14 · modified 2026-08-28

CVSS breakdown

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Attack VectorAAdjacent
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityNNone
IntegrityNNone
AvailabilityLLow

Timeline

Description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.

Affected

adobe

References

Official: NVD · CVE.org