CRITICAL

CVE-2023-26359

Adobe Coldfusion 2023-03-23 CVSS v3.1
CVSS
9.8
KEV

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

Summary dbcve.org

Adobe ColdFusion 2018 (up to Update 15) and 2021 (up to Update 5) contain a deserialization vulnerability where untrusted data is processed without proper validation, allowing an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction.

Mitigation

Apply the vendor-supplied patches (Update 16 for ColdFusion 2018 and Update 6 for ColdFusion 2021 or later) to remediate the deserialization flaw. If immediate patching is not possible, restrict network access to the ColdFusion administrator interfaces and monitor for Indicators of Compromise.

Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

16.99%
Probability of exploitation in next 30 days
96.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE