Junglewise Threat Intelligence

CVE-2025-61821: Adobe ColdFusion XXE in XML processing

CVE-2025-61821 · Severity: medium · CVSS 6.8 · Published 2025-12-10

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to the server's file system. An attacker could exploit this to read sensitive configuration files or internal data, potentially leading to further compromise of the environment. While the attack can be performed over the network without user interaction, its success depends on specific server configurations beyond the attacker's direct control.

Technical details

An Improper Restriction of XML External Entity Reference (XXE) vulnerability exists in Adobe ColdFusion. The flaw is located in the processing of XML input, where the application fails to properly restrict external entity references. A remote, unauthenticated attacker can exploit this by sending a specially crafted XML payload to the server, potentially leading to the disclosure of sensitive files from the local file system. The vulnerability is rated as medium severity because exploitation depends on specific environmental conditions (AC:H). Adobe has released security updates to address this issue in APSB25-105.

Affected products

  • Adobe ColdFusion 2025.4, 2023.16, 2021.22 and earlier

Timeline

  • 2025-12-10: disclosed: Initial disclosure by Adobe
  • 2025-12-10: advisory: Adobe security bulletin APSB25-105 published

References

Related threats