CVE-2025-61810: ColdFusion | Deserialization of Untrusted Data (CWE-502)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this vulnerability by providing maliciously crafted serialized data to the application. Exploitation of this issue requires user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61810?
CVE-2025-61810 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-61810?
To fix CVE-2025-61810, update to a version of Adobe ColdFusion that is later than 2025.4, 2023.16, and 2021.22.
What types of attacks can exploit CVE-2025-61810?
CVE-2025-61810 can be exploited by high privileged attackers to execute arbitrary code in the context of the current user.
Which versions of Adobe ColdFusion are affected by CVE-2025-61810?
CVE-2025-61810 affects Adobe ColdFusion versions 2025.4 and earlier, including 2023.16 and 2021.22.
What is the impact of CVE-2025-61810?
The impact of CVE-2025-61810 can include potential arbitrary code execution leading to unauthorized access and control over the affected system.