CVE-2023-26359

Adobe ColdFusion

Published 23 Mar 2023 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, adobe.com

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 21 Aug 2023, with a remediation deadline of 11 Sept 2023 for US federal agencies.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

References