ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Thousands of ColdFusion exploit attempts spotted during Christmas holiday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-44353
+2 in the same advisory: …26347 …44352
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

NVD description · AI analysis pending
9.8
group max
80%
  • adobe coldfusion
CVE-2023-26359
Unauthenticated Deserialization RCE in Adobe ColdFusion 2018 and 2021

Adobe ColdFusion 2018 (Update 15 and earlier) and 2021 (Update 5 and earlier) contain a deserialization of untrusted data flaw (CWE-502) that an unauthenticated attacker can trigger remotely by sending untrusted input that the server deserializes, with no user interaction or privileges required. Successful exploitation results in arbitrary code execution in the context of the current user, letting the attacker run code with the privileges of the ColdFusion process. Any organization running an affected release is exposed, particularly where ColdFusion is reachable from the internet as a web application server. The flaw carries a CVSS 3.1 score of 9.8 (critical) and an EPSS score of 17.0% probability of exploitation within 30 days (97th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-08-21. News coverage tied to the KEV addition reports the flaw is under active exploit, with thousands of ColdFusion exploitation attempts observed in the wild, including a surge during the Christmas holiday period.

Do: Upgrade ColdFusion 2018 to an update later than Update 15 and ColdFusion 2021 to an update later than Update 5 per Adobe's security advisory; if immediate patching is not possible, apply Adobe's recommended mitigations or discontinue use of the product, per CISA's KEV required action. Prioritize internet-facing ColdFusion instances and review access and application logs for signs of exploitation or post-exploitation activity, since active exploitation and mass scanning of ColdFusion servers have been reported.

9.817% KEV
  • Adobe ColdFusion 2018 (Update 15 and earlier); 2021 (Update 5 and earlier)
largetens of thousands of internet-exposed ColdFusion servers (est. 10,000-100,000)
CVE-2023-29300
+1 in the same advisory: …29298
Deserialization of Untrusted Data RCE in Adobe ColdFusion (CVE-2023-29300)

Adobe ColdFusion contains a deserialization of untrusted data flaw (CWE-502): the application deserializes attacker-supplied, untrusted serialized data without adequate validation, allowing an attacker to trigger code execution on the ColdFusion server. Successful exploitation yields arbitrary code execution in the context of the running ColdFusion server, a foothold that can be leveraged for further compromise and, per CISA, ransomware deployment. Any organization running Adobe ColdFusion is affected, especially internet-facing instances; the CISA data does not enumerate specific affected version ranges, so operators should consult Adobe's advisory for the exact affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known, but the KEV listing and ransomware usage confirm active in-the-wild exploitation.

Do: Patch every ColdFusion instance with the updates from Adobe's security advisory (APSB23-52), which satisfies the CISA required action to apply vendor mitigations or discontinue use of the product if mitigations are unavailable; prioritize internet-facing servers. If patching must be delayed, restrict network access to the ColdFusion server per vendor guidance and review logs for signs of exploitation or ransomware activity.

9.8
group max
100% KEV ransomware
  • Adobe ColdFusion
large~10,000-50,000 internet-exposed ColdFusion servers (tens of thousands), plus additional internal deployments
CVE-2023-38203
Unauthenticated Deserialization RCE in Adobe ColdFusion (Actively Exploited)

CVE-2023-38203 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in Adobe ColdFusion that can lead to arbitrary code execution. It is triggered over the network when an affected ColdFusion server processes crafted untrusted serialized data, and exploitation requires no authentication and no user interaction. A successful attacker gains arbitrary code execution with high impact on confidentiality, integrity, and availability of the host. Organizations running ColdFusion 2018 (Update 17 or earlier), ColdFusion 2021 (Update 7 or earlier), or ColdFusion 2023 (Update 1 or earlier) are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile), and Adobe has shipped out-of-band patches in response.

Do: Upgrade all ColdFusion 2018, 2021, and 2023 installations beyond the affected levels (at least past 2018u17, 2021u7, and 2023u1, using the latest update Adobe provides in its advisory). If patching must be delayed, apply the mitigations per Adobe's instructions, restrict or remove internet exposure of ColdFusion servers, and prioritize internet-facing hosts. Because exploitation is confirmed with known ransomware use, review ColdFusion logs and affected hosts for signs of exploitation, webshells, or follow-on malware, and discontinue use of the product if mitigations are unavailable per CISA's required action.

9.897% KEV ransomware
  • adobe coldfusion ColdFusion 2018 releases up to and including Update 17 (2018u17)
  • adobe coldfusion ColdFusion 2021 releases up to and including Update 7 (2021u7)
  • adobe coldfusion ColdFusion 2023 releases up to and including Update 1 (2023u1)
large~tens of thousands of internet-facing ColdFusion servers (order of 10,000-100,000 exposed instances); total install base including internal deployments is…
CVE-2023-38205
+1 in the same advisory: …38204
Security Feature Bypass in Adobe ColdFusion Exposes Admin CFM/CFC Endpoints

CVE-2023-38205 is an improper access control flaw (CWE-284) in the administration interface of Adobe ColdFusion that results in a security feature bypass. It can be triggered over the network with no authentication and no user interaction, by sending requests directly to the ColdFusion administrative CFM and CFC endpoints. An attacker who exploits it gains unauthorized access to those admin endpoints, with the CVSS vector indicating high confidentiality impact (no direct integrity or availability impact). Any organization running an unpatched ColdFusion 2018 (Update 18 or earlier), 2021 (Update 8 or earlier), or 2023 (Update 2 or earlier) instance is affected, particularly where the admin endpoints are reachable from untrusted networks. The flaw is being actively exploited: it was added to the CISA KEV catalog on 2023-07-20, EPSS assigns a 99.7% probability of exploitation within 30 days, and related news describes an out-of-band Adobe patch for an actively exploited ColdFusion zero-day plus thousands of observed ColdFusion exploit attempts, with companion flaws (CVE-2023-38203, CVE-2023-29298) used to deploy web shells; no standalone public PoC is known, but the KEV listing confirms in-the-wild use.

Do: Apply Adobe's July 2023 out-of-band updates by upgrading to ColdFusion 2018 Update 19, 2021 Update 9, and 2023 Update 3, or later. Until patched, restrict network access to the ColdFusion Administrator CFM/CFC endpoints (the standard /CFIDE/administrator area) and review servers for compromise indicators such as web shells, given the companion ColdFusion flaws were exploited to deploy web shells. As a CISA KEV entry, federal and other KEV-bound operators must apply the vendor mitigations or discontinue use of the product if mitigations are unavailable.

7.5
group max
100% KEV
  • Adobe ColdFusion 2018 Update 18 and earlier
  • Adobe ColdFusion 2021 Update 8 and earlier
  • Adobe ColdFusion 2023 Update 2 and earlier
largetens of thousands of internet-exposed ColdFusion servers (roughly 30,000-50,000), plus a larger installed base behind firewalls
CVE-2024-20767
Improper Access Control in Adobe ColdFusion Enables Arbitrary File Read

Adobe ColdFusion contains an improper access control flaw (CWE-284) that allows an unauthenticated attacker to read arbitrary files on the server's file system; per Adobe's advisory, an attacker could also access or modify restricted files. Exploitation occurs over the network with no authentication and no user interaction, but it requires the ColdFusion Administrator panel to be exposed to the internet. A successful attacker can retrieve restricted files, potentially exposing sensitive configuration and credential material stored on the server. Organizations running ColdFusion 2023.6 or earlier on the 2023 release, or 2021.12 or earlier on the 2021 release, with the admin panel reachable from the internet are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, thousands of exploit attempts were observed during the Christmas holiday, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade ColdFusion 2023 to a version later than 2023.6 and ColdFusion 2021 to a version later than 2021.12 per Adobe's advisory and CISA's required action. If patching must be deferred, keep the ColdFusion Administrator panel off the public internet by restricting it via firewall, VPN, or IP allowlisting, since internet exposure of the admin panel is required for exploitation. Given the KEV listing (2024-12-16) and thousands of observed exploit attempts over the Christmas holiday, organizations with internet-exposed ColdFusion servers should review logs for exploitation activity and treat prior exposure as a potential compromise.

7.499% KEV
  • Adobe ColdFusion 2023 2023.6 and earlier
  • Adobe ColdFusion 2021 2021.12 and earlier
largeon the order of 10,000-100,000 potentially exposed systems (tens of thousands of internet-reachable ColdFusion servers, of which only those with the…
Full article478 words · extracted from securityaffairs.com · click to collapse

GreyNoise observed thousands of attacks targeting about a dozen Adobe ColdFusion vulnerabilities during the Christmas 2025 holiday.

GreyNoise reports a coordinated campaign exploiting about a dozen Adobe ColdFusion vulnerabilities, with thousands of attack attempts observed during the Christmas 2025 holiday.

“GreyNoise observed a coordinated exploitation campaign targeting Adobe ColdFusion servers over the Christmas 2025 holiday period.” reads the report published by GreyNoise. “The attack appears to be a single threat actor operating from Japan-based infrastructure (CTG Server Limited). This source was responsible for ~98% of attack traffic, systematically exploiting 10+ ColdFusion CVEs from 2023-2024.”

A single actor, using Japan-based infrastructure, generated about 98% of the traffic and exploited more than 10 ColdFusion CVEs from 2023–2024. The attacks used ProjectDiscovery Interactsh for out-of-band verification, with JNDI/LDAP injection as the main vector. Most activity occurred on Christmas Day, suggesting deliberate timing to exploit reduced security monitoring.

The researchers observed 5,940 malicious requests exploiting ColdFusion vulnerabilities from 2023–2024, peaking on December 25.

Most of the requests targeted servers in the US (4,044), Spain (753), and India (128).

GreyNoise identified a dominant threat actor using two IPs (134.122.136[.]119, 134.122.136[.]96) hosted by CTG Server Limited (AS152194), responsible for nearly all observed ColdFusion exploitation traffic. The two IPs accounted for over 98% of requests, operated concurrently in many cases, shared Interactsh sessions, and showed automated, coordinated behavior cycling through multiple attack types. Minor activity came from a handful of secondary IPs across Canada, India, the US, and Cloudflare. CTG Server Limited, a Hong Kong–registered provider with rapid IP space growth, has prior links to phishing, spam, bogon routing, and weak abuse enforcement, raising concerns about its role as a permissive hosting environment.

Below is the list of targeted ColdFusion vulnerabilities:

CVETypeRequests
Generic RCERemote Code Execution1,403
Generic LFILocal File Inclusion904
CVE-2023-26359Deserialization RCE833
CVE-2023-38205Access Control Bypass654
CVE-2023-44353Remote Code Execution611
CVE-2023-38203Remote Code Execution346
CVE-2023-38204Remote Code Execution346
CVE-2023-29298Access Control Bypass342
CVE-2023-29300Remote Code Execution176
CVE-2023-26347Access Control Bypass171
CVE-2024-20767Arbitrary File Read146
CVE-2023-44352Reflected XSS8

Analysis shows the ColdFusion activity was only about 0.2% of a much larger vulnerability scanning campaign conducted from the same two IPs. Overall, the operation generated more than 2.5 million requests, targeting a total of 767 CVEs spanning 2001–2025, with over 1,200 attack signatures and thousands of unique fingerprints and OAST domains.

The campaign focused mainly on reconnaissance, followed by CVE exploitation, LFI, and RCE attempts. It targeted more than 47 technology stacks, including Java application servers, web frameworks, CMS platforms, network devices, and enterprise software. The scale, breadth of CVEs, and automation indicators point to a systematic, template-based reconnaissance effort covering the global vulnerability landscape.

The experts published Indicators of Compromise for this campaign.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Adobe)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/186450/hacking/thousands-of-coldfusion-exploit-attempts-spotted-during-christmas-holiday.html