ZeroHour

CVE-2023-26360

KEV PoC large1

Unauthenticated RCE via Improper Access Control in Adobe ColdFusion

CISA: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 3.1
8.6 high
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2023-26360 is an improper access control flaw (CISA categorizes it as deserialization of untrusted data) in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Update 5 and earlier). It can be triggered over the network with no authentication and no user interaction. A successful attacker achieves arbitrary code execution in the context of the current user, giving them full control of the ColdFusion server. Any organization running the affected ColdFusion versions is exposed, particularly those with instances reachable from the internet; public reporting confirms exploitation in the wild, including a breach of federal agency servers. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-15, has a public proof-of-concept, and carries a 97.3% EPSS probability of exploitation within 30 days.

What to do: Apply Adobe's updates per vendor instructions, upgrading ColdFusion 2018 beyond Update 15 and ColdFusion 2021 beyond Update 5. Because exploitation is unauthenticated and confirmed in the wild (including against a federal agency), prioritize patching internet-facing servers, restrict ColdFusion endpoints to trusted networks in the interim, and hunt for signs of compromise such as web shells, unexpected processes, and suspicious connections (reported activity includes malicious web shell use). Organizations that cannot patch immediately should at minimum limit exposure and monitor for exploitation attempts.

Affected
Adobe ColdFusion2018 Update 15 and earlier
Adobe ColdFusion2021 Update 5 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (public scan data), with many more internal/enterprise deployments — Internet-wide scans of the ColdFusion install base have historically shown on the order of tens of thousands of exposed instances, and the product remains widely deployed in enterprise and government environments, so this is an estimate of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news