CVE-2025-30285
largeDeserialization RCE in Adobe ColdFusion (2025.0, 2023.12, 2021.18 and earlier)
CVE-2025-30285 is a deserialization of untrusted data flaw (CWE-502) in Adobe ColdFusion that can result in arbitrary code execution in the context of the current user. The attack vector is the network, but exploitation requires a high-privileged attacker (PR:H) and user interaction (UI:R); once triggered, the attacker bypasses security protections and executes code with scope changed, extending impact beyond the vulnerable component (confidentiality, integrity and availability all rated high). The flaw affects all currently supported ColdFusion release trains listed in the advisory — 2025.0, 2023.12 and 2021.18 and their earlier versions — so nearly any organization running ColdFusion is in scope. As of the dashboard data the issue is not in CISA KEV and no public proof-of-concept is known, but a high EPSS of 29.5% (98th percentile) signals an elevated likelihood of exploitation within 30 days. Adobe shipped the fix as part of a batch addressing 30 ColdFusion vulnerabilities, of which 11 were rated critical.
What to do: Upgrade every ColdFusion 2025, 2023 and 2021 instance to a release newer than 2025.0, 2023.12 and 2021.18 respectively, using Adobe's current security update set that also patches the other critical ColdFusion issues in the same advisory batch. Until patched, restrict network access to ColdFusion servers and limit high-privileged account usage, since exploitation requires an already high-privileged attacker plus user interaction; review deserialization-related endpoints and monitor for exploitation attempts given the high EPSS.
| adobe coldfusion | 2025.0 and earlier |
| adobe coldfusion | 2023.12 and earlier |
| adobe coldfusion | 2021.18 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H