PT-2023-1713 · Adobe · Coldfusion
CVE-2023-26360
·
Published
2023-03-14
·
Updated
2026-07-01
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions prior to 2018 Update 16
Adobe ColdFusion versions prior to 2021 Update 6
Description
An improper access control issue involving the deserialization of untrusted data allows a remote attacker to execute arbitrary code in the context of the current user without requiring user interaction. This flaw has been exploited in the wild to gain initial access to U.S. federal government servers.
Recommendations
Update Adobe ColdFusion 2018 to Update 16 or a newer version.
Update Adobe ColdFusion 2021 to Update 6 or a newer version.
Exploit
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion