CVE-2023-26360: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Other sources
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26360?
CVE-2023-26360 is a vulnerability in Adobe ColdFusion that allows for remote code execution through the deserialization of untrusted data.
How severe is CVE-2023-26360?
CVE-2023-26360 is a critical vulnerability that allows attackers to execute arbitrary code on a vulnerable Adobe ColdFusion server.
How can I fix CVE-2023-26360?
To fix CVE-2023-26360, apply the latest security patch provided by Adobe and ensure that ColdFusion is updated to a non-vulnerable version.
Is there any workaround for CVE-2023-26360?
Currently, there are no known workarounds for CVE-2023-26360. Applying the security patch is the recommended solution.
Where can I find more information about CVE-2023-26360?
You can find more information about CVE-2023-26360 on the Adobe Security Bulletin APSB23-25.