Junglewise Threat Intelligence

CVE-2023-26359: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVE-2023-26359 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-08-21

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to deserialization of untrusted data. An unauthenticated attacker can exploit this to execute arbitrary code in the context of the current user without requiring user interaction.

Affected products

  • Adobe ColdFusion 2018 Update 15 and earlier
  • Adobe ColdFusion 2021 Update 5 and earlier

Timeline

  • 2023-03-23: disclosed: NVD Published Date
  • 2023-08-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-21: patched: Patch reference updated in advisory

Related threats