Threat actors breached US govt systems by exploiting Adobe ColdFusion flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-26360 | Unauthenticated RCE via Improper Access Control in Adobe ColdFusion CVE-2023-26360 is an improper access control flaw (CISA categorizes it as deserialization of untrusted data) in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Update 5 and earlier). It can be triggered over the network with no authentication and no user interaction. A successful attacker achieves arbitrary code execution in the context of the current user, giving them full control of the ColdFusion server. Any organization running the affected ColdFusion versions is exposed, particularly those with instances reachable from the internet; public reporting confirms exploitation in the wild, including a breach of federal agency servers. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-15, has a public proof-of-concept, and carries a 97.3% EPSS probability of exploitation within 30 days. Do: Apply Adobe's updates per vendor instructions, upgrading ColdFusion 2018 beyond Update 15 and ColdFusion 2021 beyond Update 5. Because exploitation is unauthenticated and confirmed in the wild (including against a federal agency), prioritize patching internet-facing servers, restrict ColdFusion endpoints to trusted networks in the interim, and hunt for signs of compromise such as web shells, unexpected processes, and suspicious connections (reported activity includes malicious web shell use). Organizations that cannot patch immediately should at minimum limit exposure and monitor for exploitation attempts. | 8.6 | 97% | KEV PoC |
| largetens of thousands of internet-exposed ColdFusion servers (public scan data), with many more internal/enterprise deployments |
Full article421 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 06, 2023

The U.S. CISA warns that threat actors are actively exploiting a critical vulnerability in Adobe ColdFusion to breach government agencies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about threat actors actively exploiting a critical vulnerability (CVE-2023-26360) in Adobe ColdFusion to breach government agencies.
The flaw is an Improper Access Control that can allow a remote attacker to execute arbitrary code. The vulnerability could also lead to arbitrary file system read and memory leak.
The vulnerability impacts Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier).
In March 2023, threat actors exploited the vulnerability in attacks against government agencies. At the time the flaw was a zero-day and U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the critical vulnerability CVE-2023-26360 (CVSS score: 8.6) to its Known Exploited Vulnerabilities Catalog.
The US Cyber Defense Agency is now warning that threat actors are still exploiting the flaw CVE-2023-26360 in attacks. The Agency revealed that the attacks breached two federal agency systems in June.
The impacted servers were both running outdated versions of software.
The attackers dropped malware using HTTP POST commands to the directory path associated with ColdFusion.
“In June 2023, through the exploitation of CVE-2023-26360, threat actors were able to establish an initial foothold on two agency systems in two separate instances. In both incidents, Microsoft Defender for Endpoint (MDE) alerted of the potential exploitation of an Adobe ColdFusion vulnerability on public-facing web servers in the agency’s pre-production environment. Both servers were running outdated versions of software which are vulnerable to various CVEs.” reads the alert published by US CISA. “Additionally, various commands were initiated by the threat actors on the compromised web servers; the exploited vulnerability allowed the threat actors to drop malware using HTTP POST commands to the directory path associated with ColdFusion.”
The experts believe that the exploitation was part of a reconnaissance activity conducted by the threat actor.
The first incident took place as early as June 26, 2023, the threat actors exploited the flaw to breach a web server running Adobe ColdFusion v2016.0.0.3.
The second incident took place as early as June 2, 2023, the threat actors exploited the flaw to breach a web server running Adobe ColdFusion v2021.0.0.2.
There is no evidence of successful data exfiltration or lateral movement during either incident. The impacted agencies were able to lock out the attackers within 24 hours.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155289/security/us-govt-adobe-coldfusion-flaw.html