CVE-2025-54261
largeCritical Path Traversal Leading to RCE in Adobe ColdFusion 2025/2023/2021
CVE-2025-54261 is an Improper Limitation of a Pathname to a Restricted Directory (path traversal, CWE-22) flaw in Adobe ColdFusion that allows an attacker to escape a restricted directory and achieve arbitrary code execution. It is remotely exploitable over the network with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), but only on servers where certain optional configurations are enabled. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope rating indicates the attacker's impact can cross the vulnerable component's security boundary (e.g., reach other system resources). Affected deployments are ColdFusion 2025, 2023, and 2021 servers on update levels 2025.3, 2023.15, and 2021.21 or earlier that have the relevant optional configuration active. There is no public proof-of-concept and the flaw is not yet in CISA's KEV, but the ~21% EPSS probability (97th percentile) signals elevated risk of exploitation in the next 30 days, so patching should be treated as urgent.
What to do: Upgrade every ColdFusion 2025, 2023, and 2021 installation to the latest update release beyond 2025.3 / 2023.15 / 2021.21 per Adobe's September 2025 security bulletin, prioritizing internet-facing servers given the elevated EPSS. Inventory deployments for the optional configurations implicated by the advisory and, until patched, restrict network access to ColdFusion endpoints (e.g., at the firewall/reverse-proxy layer). Monitor Adobe's advisory and CISA KEV for confirmation of active exploitation.
| Adobe ColdFusion 2025 | 2025.3 and earlier |
| Adobe ColdFusion 2023 | 2023.15 and earlier |
| Adobe ColdFusion 2021 | 2021.21 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H