Junglewise Threat Intelligence

CVE-2023-26360: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVE-2023-26360 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-03-15

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to deserialization of untrusted data due to improper access control. This flaw allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user without any interaction.

Affected products

  • Adobe ColdFusion 2018 Update 15 and earlier
  • Adobe ColdFusion 2021 Update 5 and earlier

Timeline

  • 2023-03-15: disclosed
  • 2023-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-23: advisory: NVD Published Date
  • 2023-03-15: patched: Adobe released APSB23-25 advisory and patches
  • 2023-03-15: exploited: Reported as exploited in the wild at time of publication

Related threats