Executive brief
Adobe ColdFusion contains a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected system.
Affected products
- Adobe ColdFusion 2016 Update 3 and earlier
- Adobe ColdFusion 11 Update 11 and earlier
- Adobe ColdFusion 10 Update 22 and earlier
Timeline
- 2017-04-25: advisory: Original Adobe advisory APSB17-14 published
- 2025-02-24: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-02-24: exploited: Confirmed as exploited in the wild per CISA KEV entry