CVE-2023-26360
KEV PoC large1Unauthenticated RCE via Improper Access Control in Adobe ColdFusion
CISA: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
CVE-2023-26360 is an improper access control flaw (CISA categorizes it as deserialization of untrusted data) in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Update 5 and earlier). It can be triggered over the network with no authentication and no user interaction. A successful attacker achieves arbitrary code execution in the context of the current user, giving them full control of the ColdFusion server. Any organization running the affected ColdFusion versions is exposed, particularly those with instances reachable from the internet; public reporting confirms exploitation in the wild, including a breach of federal agency servers. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-15, has a public proof-of-concept, and carries a 97.3% EPSS probability of exploitation within 30 days.
What to do: Apply Adobe's updates per vendor instructions, upgrading ColdFusion 2018 beyond Update 15 and ColdFusion 2021 beyond Update 5. Because exploitation is unauthenticated and confirmed in the wild (including against a federal agency), prioritize patching internet-facing servers, restrict ColdFusion endpoints to trusted networks in the interim, and hunt for signs of compromise such as web shells, unexpected processes, and suspicious connections (reported activity includes malicious web shell use). Organizations that cannot patch immediately should at minimum limit exposure and monitor for exploitation attempts.
| Adobe ColdFusion | 2018 Update 15 and earlier |
| Adobe ColdFusion | 2021 Update 5 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
- Affected
- Adobe ColdFusion
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N